womtexx[.]com
“Womtexx: Most Popular Online Crypto Casino Based on Blockchain”
Зведення доказів
This domain, womtexx.com, was registered on August 30 2025 through NiceNIC International Group Co., Limited and resolved to the Cloudflare edge address 172.67.220.204 (AS13335, United States). The site presented the page title “Womtexx: Most Popular Online Crypto Casino Based on Blockchain” and was classified as a crypto‑scam impersonating the legitimate brand x.com. No TLS certificate was observed, indicating the site operated without HTTPS protection. Cloudflare nameservers isaac.ns.cloudflare.com and rafe.ns.cloudflare.com were listed, confirming the use of the Cloudflare CDN for hosting.
Malware and phishing detection services flagged the domain; VirusTotal reported 7 of 95 security vendors as positive, and the site was listed on at least one external blocklist and actively blocked by PhishDestroy. The Gridinsoft trust score of 1/100 further reflects a high likelihood of malicious intent. The phishing kit identified as “Gambler Scam” aligns with the cryptocurrency casino theme. As of the report date, the domain has been taken offline, but the infrastructure—especially the use of Cloudflare’s network and the absence of SSL—remains a potential indicator for future re‑hosting.
Defenders should continue to monitor the domain’s DNS records for any re‑activation, add the IP address 172.67.220.204 to deny‑list rules where appropriate, and include womtexx.com in brand‑monitoring feeds for x.com. Correlation with other Gambler Scam kit deployments may reveal additional campaign infrastructure. At present, no further technical artefacts such as payload samples or URL structures have been disclosed, so the precise attack vector remains uncertain.
Data Coverage
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Збережені докази результату
Результат і атрибуція блокування
- Результат
held- Доступність
unreachable- Причина
registrar_client_hold- Учасник
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Механізм
client_hold- Упевненість
- 95%
- Перше спостереження
- Останнє спостереження
Оцінка часу недоступності
Час до недоступності: 0 hSHA-256 доказу 77642ae12f99
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Доступність
Перше збережене значення: DNS неактивний
f93a11f87e4d -
Доступність
DNS неактивний → Невідомо
953d79d44a3f -
Доступність
Невідомо → Утримується
b85e7d6842d1 -
Доступність
Утримується → Неактивний
966c87b9230f -
Доступність
Неактивний → DNS неактивний
1009e28898ff -
Доступність
DNS неактивний → Невідомо
4e59611f78b8 -
Доступність
Невідомо → Утримується
881babc03f11 -
Доступність
Утримується → Невідомо
317e98b328eb -
Доступність
Невідомо → DNS неактивний
6dfe9145995c
Показати всі (10)
-
Доступність
DNS неактивний → Утримується
de7568d15d5a -
Доступність
Утримується → DNS неактивний
641ed81dc4d5 -
Доступність
DNS неактивний → Невідомо
b1b2f228aa48 -
Доступність
Невідомо → Утримується
2d7b1519cf8b -
Доступність
Утримується → Невідомо
31da42e80abb -
Доступність
Невідомо → DNS неактивний
d0b7046e8c2f -
Доступність
DNS неактивний → Утримується
8674e1d1cf1c -
Доступність
Утримується → DNS неактивний
ca9ed662b468 -
Доступність
DNS неактивний → Невідомо
04617d8cea98 -
Доступність
Невідомо → Утримується
77642ae12f99
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 28.09.2025
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога