VirusTotal
14 / 93
“Spinroyal: Most Popular Online Crypto Casino Based on Blockchain”
spinroyal.online — Неперевірений. Уособлення бренду: Genericcrypto; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
14 / 93
100 det.
malicious
Повідомити1/100
ПовідомитиDBL_PHISH
11 community references
Повідомитиprovider verdict: suspicious
Повідомитизбережений звіт
Повідомити Checked; no threat flag recorded
ПовідомитиAnalysis of spinroyal.online indicates that the domain was registered on August 27, 2025 through NiceNIC International Group Co., Limited and is served by Cloudflare nameservers felicity.ns.cloudflare.com and janet.ns.cloudflare.com. The site resolves to the Cloudflare IP 104.21.24.54, which belongs to AS13335 (Cloudflare, Inc.) and is geolocated in the United States. The TLS certificate presented for the domain lists Internet Widgits Pty Ltd as the issuing organization. HTTP inspection shows the page title “Spinroyal: Most Popular Online Crypto Casino Based on Blockchain”. The underlying web server stack is identified as Nginx with OpenResty. The domain is associated with a Gambler Scam phishing kit and is categorized as a crypto‑related scam. VirusTotal reports 14 of 93 scanning engines flag the domain as malicious. Independent blocklists, including PhishDestroy, have listed the domain, and a proprietary Gridinsoft trust score assigns it a rating of 1 out of 100. The site is currently taken offline, and it appears on only one additional security blocklist.
The available evidence confirms that spinroyal.online was used to host a crypto‑casino phishing campaign, but the exact content of the landing pages has not been captured in the public feed. No further indicators such as malicious payload hashes, command‑and‑control endpoints, or compromised credentials have been disclosed, leaving the full scope of victim targeting and data exfiltration uncertain.
Defenders should block the domain at network perimeter and DNS resolvers, add the associated IP 104.21.24.54 to blacklists, and monitor for any outbound connections to Cloudflare edge nodes that may be leveraged for future campaigns. Continuous re‑scanning of the domain is advised in case it is re‑hosted, and security teams should update email and web filters with the observed page title and kit signatures.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Примітка щодо сканера: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='spinroyal.online', port=80): Max retries exceeded with url: / (Caused by NewConnectionErro
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Репутація Edge-IP не пов’язана з цим доменом.
felicity.ns.cloudflare.comjanet.ns.cloudflare.comLocation describes the IP network.
5629d6087ff4a1519973aae7fb3cfb818218d6fbb111291121cb43d9b9235197Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of spinroyal.online · checked Apr 23, 2026
17 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 25.12.2025
PD-1779593358-spinroyal.onlin Recipient: abuse@nicenic.net Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога