MALICIOUS — HIGH
winnaria[.]com
The domain winnaria.com was registered on July 24, 2025 through NiceNIC International Group Co., Limited and is currently listed as offline.
- VirusTotal
- 2/95
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
winnaria.com — Контент недоступен (HTTP 502). Олицетворение бренда: Foundation; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/95 (alphaMountain.ai, Fortinet); PhishDestroy score 61/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain winnaria.com was registered on July 24, 2025 through NiceNIC International Group Co., Limited and is currently listed as offline. The site resolved to the IPv4 address 69.5.189.54, which belongs to AS42624 Global-Data System IT Corporation and is geolocated in Switzerland (CH). No TLS certificate was presented, indicating clear‑text HTTP only. The authoritative name servers are ns1.nameserverhub.com, ns2.nameserverhub.com, ns3.nameserverhub.com, and ns4.nameserver.
The page title returned by the server reads “WINNARIA | Play at the best online casino based on Blockchain”, matching the documented “Crypto Scam” classification and the “Gambler Scam” kit. The campaign impersonates the foundation brand, as indicated by the intelligence feed. Reputation scoring from Gridinsoft assigns a trust score of 1 out of 100, reflecting extreme maliciousness. The domain is present on one security blocklist and has been actively blocked by the PhishDestroy service.
VirusTotal analysis shows that two of ninety‑five scanning engines flagged the domain, confirming malicious behavior. Defenders should add 69.5.189.54 and the full domain name to network‑level deny lists, enforce HTTPS‑only policies to prevent accidental clear‑text connections, and monitor the NiceNIC registrar for any new registrations that reuse the same name servers or similar kit signatures. Continuous hunting for the Gambler Scam kit artifacts in email and web traffic is recommended, as well as periodic re‑scanning of the domain should it reappear. The elevated risk rating reflects the combination of low trust score, brand impersonation, and active blocklist presence.
Охват данных13 recorded checks
Сигналы безопасности
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:33:47 UTC
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.