riowinz[.]lat
“Riowinz: Most Popular Online Crypto Casino Based on Blockchain”
riowinz.lat — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Genericcrypto; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 9/93 (ADMINUSLabs, G-Data, Kaspersky, SOCRadar, Sophos); URLScan malicious verdict; PhishDestroy score 77/100. Kayıt kuruluşu: Global Domain Group.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, riowinz.lat, was observed hosting a site titled “Riowinz: Most Popular Online Crypto Casino Based on Blockchain”. The content aligns with a crypto‑scam phishing campaign that uses the publicly known Gambler Scam kit. VirusTotal records indicate that nine of ninety‑three scanning engines flagged the domain as malicious, demonstrating partial detection across the security community. The site has been listed on at least one security blocklist and is actively blocked by the PhishDestroy service, reinforcing its classification as a malicious resource.
Infrastructure analysis shows the domain is served from the Cloudflare network (AS13335) with the IP address 172.67.155.127, and the nameservers kiki.ns.cloudflare.com and matias.ns.cloudflare.com resolve to the same provider. No TLS certificate was presented, meaning the site operated without HTTPS protection. Registration data reveal the domain was created on 26 February 2026 and was registered through Global Domain Group LLC. The domain’s current HTTP status is offline, and it has been taken down, but the historical evidence remains relevant for threat‑intelligence feeds.
Defenders should continue to block riowinz.lat at the DNS and proxy layers, monitor for any re‑use of the associated IP address or nameserver set, and add the observed indicators to internal blacklists. Because the site employed a known gambling‑focused phishing kit, future campaigns may target similar cryptocurrency or gambling‑related victims; threat‑hunting queries that include the page title, the IP 172.67.155.127, or the “Gambler Scam” signature can help surface related activity. At present, no additional payload or command‑and‑control infrastructure has been disclosed, so further investigation is required to determine whether the domain was part of a broader campaign.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260227-C512C6 Recipient: abuse@globaldomaingroup.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin