MALICIOUS — CRITICAL
venowin[.]com
venowin.com is a confirmed credential harvesting domain currently active and posing as WinRAR, a popular file compression utility.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
venowin.com — Bilinen son aktif (HTTP 301). Marka kimliğine bürünme: Genericcrypto; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 1/91 (Gridinsoft); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 86/100. Kayıt kuruluşu: Fewmoretaps OU d/b/a T….
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
venowin.com is a confirmed credential harvesting domain currently active and posing as WinRAR, a popular file compression utility. Security analysts have classified this domain as a generic phishing site with an elevated risk level, indicating active attempts to deceive users into surrendering sensitive information such as login credentials or financial details.
This domain was flagged by 1 of 95 VirusTotal security vendors, indicating limited but notable detection by antivirus engines. The domain was registered through Fewmoretaps OU d/b/a Trustname.com, resolves to IP address 172.67.172.85, and was created on May 03, 2026. It utilizes a Let's Encrypt SSL certificate, which may contribute to a false sense of legitimacy among users. Despite its recent registration, the domain's association with phishing activity has been confirmed by multiple threat intelligence sources.
Given the active status of venowin.com and its confirmed use in credential harvesting campaigns, users are strongly advised to avoid interacting with this domain. If accidental access occurs, do not input any personal or financial information. Security teams should consider blocking this domain at the network level and updating blocklists to prevent further exposure. Report any observed phishing activity to relevant authorities or cybersecurity platforms to aid in ongoing threat mitigation efforts.
Veri kapsamı14 recorded checks
Güvenlik Sinyalleri
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Teknolojiler · 4 identified
Twitter Ads is an advertising platform for Twitter 'microblogging' system.
ads.twitter.com %100 güvenFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com %100 güvenCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of venowin.com · checked May 9, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260508-3922D1 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.