MALICIOUS — CRITICAL
winara[.]cc
11 of 94 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 11/94
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
winara.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcrypto; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 11/94 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 87/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Digest
winara.cc is classified critical with an evidence score of 87/100. 11 of 94 security engines flagged the domain. Registered 19 Mar 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 2 outgoing abuse reports are recorded, most recently on 20 Apr 2026.
Stored generated summary (templated)mistral · 20.04.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies winara.cc as an elevated-risk crypto drainer domain impersonating a legitimate brand to steal cryptocurrency assets. The domain was registered on March 19, 2026, and is currently active with a Let's Encrypt SSL certificate, indicating an attempt to appear trustworthy. This drainer kit likely uses deceptive web interfaces to trick victims into connecting crypto wallets, prompting fraudulent transactions.
This domain exhibits multiple technical indicators of malicious intent. VirusTotal analysis shows 8 out of 95 security vendors flagging winara.cc as malicious. The domain resolves to IP address 188.114.97.3 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain’s recent creation date (March 19, 2026) suggests a short-lived campaign designed for rapid deployment and evasion. No current blocklist presence is confirmed, but the low VT detection rate implies many security tools remain unaware of the threat.
As of this report, winara.cc remains active with an elevated risk level, meaning it is actively targeting potential victims. Immediate response actions include blocking the domain at the network level, flagging the associated IP in firewall rules, and updating browser-based security tools to prevent access. Despite these measures, the domain’s recent registration and low detection rate leave a residual risk that it may evade some defenses. Continuous monitoring and threat intelligence updates are recommended to mitigate ongoing exposure.
Охват данных12 recorded checks
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | winara.cc |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Latest Classified Outcome 2026-08-09 04:33:46 UTC
Технологии · 4 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of winara.cc · checked Apr 20, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260420-4E4212 Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.