Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
onwin2449[.]net
“Barclays.Net”
Kanıt özeti
This domain, onwin2449.net, was identified as a phishing infrastructure specifically designed to impersonate Barclays, a major financial institution. The site operated with the intent to deceive users into divulging sensitive banking credentials, including login details, personal identification numbers, and financial transaction data. Analysis of the domain reveals it hosted fraudulent pages mimicking Barclays' official online banking portal, likely employing social engineering tactics such as urgent account verification requests or fake security alerts to manipulate victims into submitting their credentials. The domain's page title, 'Sorry, the website has been stopped,' suggests it was recently taken offline, potentially following detection or enforcement action, though residual risk remains for users who may have interacted with it prior to deactivation. Evidence supporting the malicious classification of onwin2449.net includes multiple technical indicators. The domain was flagged by 23 out of 95 security vendors on VirusTotal, indicating broad consensus among threat intelligence sources regarding its fraudulent nature. Registered through Internet Domain Service BS Corp. on September 21, 2025, the domain's recent creation aligns with common phishing lifecycle patterns, where newly registered domains are frequently abused for short-term campaigns. Infrastructure analysis reveals the domain resolved to the IP address 91.92.240.61, hosted under AS202412 (Omegatech LTD) in Germany, a network previously associated with malicious activity. Additionally, the domain appears on at least one security blocklist, and its SSL certificate, issued by Let's Encrypt (R13), was likely used to lend an appearance of legitimacy to the fraudulent site. The combination of these factors—recent registration, high detection rate, and association with known malicious infrastructure—elevates the risk assessment for this domain. Users who visited onwin2449.net or interacted with any content hosted on this domain should take immediate corrective action to mitigate potential compromise. First, any credentials entered on the site must be considered exposed and should be changed immediately across all platforms where the same or similar passwords were used. Affected individuals should contact Barclays directly through verified channels to report potential fraud and monitor their accounts for unauthorized transactions. Enabling multi-factor authentication on all financial and sensitive accounts is strongly recommended to prevent unauthorized access, even if credentials were compromised. Additionally, users should review their systems for signs of malware or unauthorized access, as phishing sites may distribute malicious payloads or redirect to secondary infection vectors. Organizations should update their security controls to block the domain and its associated IP address (91.92.240.61) to prevent further exposure.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260214-3C04CF- Yakalanan sayfa başlığı
- Sorry, the website has been stopped
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Acceptable Use Policy (AUP): The domain onwin2449.net is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the ongoing fraudulent activities associated with this domain warrant immediate action.
Applicable Laws (IS):
Act on Electronic Communications and the Protection of Privacy (No. 81/2003): This law prohibits unauthorized access to data and fraudulent use of electronic communications, which is applicable to the phishing activities conducted by this domain.
Criminal Code of Iceland (No. 19/1940), Chapter 27: This chapter addresses fraud and deception, making it illegal to deceive individuals for financial gain, which is precisely what phishing entails.
Regulatory Note: Failure to take immediate action against onwin2449.net may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance could expose your organization to legal repercussions.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | onwin2449.net |
malicious | Sinkholed |
| OpenDNS | onwin2449.net |
phishing | Phishing Block |
| DigiCert UltraDNS | onwin2449.net |
malicious | Sinkholed |
| Quad9 DNS | onwin2449.net |
malicious | Sinkholed |
| DNS4EU | onwin2449.net |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilemiyor → Erişilebilir
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin