Chuyển đến báo cáo bảo mật
Checked 09/08/2026 Ref 4FF2EC70

MALICIOUS — HIGH

gusewin[.]com

This domain is flagged as an elevated-risk brand impersonation scheme targeting cryptocurrency gambling platforms.

67/100 evidence score · High
VirusTotal
4/91
Blocklists
No stored match
sẵn có
Có thể truy cập · hạn chế quyền truy cập · HTTP 403
Report / Add Evidence Appeal this listing
2026-05-10 22:11 UTCCó thể truy cập · hạn chế quyền truy cập · HTTP 403

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Tên miền này đã bị đánh dấu là có hại
Công cụ bảo mật báo cáo phát hiện: 4. Hãy hết sức thận trọng — không nhập thông tin xác thực hoặc thông tin cá nhân.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
2
Latest case ID
PD-1778458291-gusewin.com
Current status
HTTP 403 at latest stored check
Jump to section
Tóm tắt báo cáo

gusewin.com — Có thể truy cập · hạn chế quyền truy cập (HTTP 403). Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); URLQuery 6 alerts; PhishDestroy score 67/100. Nhà đăng ký: Fewmoretaps OU d/b/a T….

Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.

Evidence Analysis

Ref 4FF2EC70

gusewin.com: Confirmed Brand Impersonation Crypto Casino Scam

This domain is flagged as an elevated-risk brand impersonation scheme targeting cryptocurrency gambling platforms.

This domain is flagged as an elevated-risk brand impersonation scheme targeting cryptocurrency gambling platforms. Analysis indicates gusewin.com mimics legitimate crypto casino services, presenting itself as 'Pazewin: Most Popular Online Crypto Casino Based on Blockchain' to deceive users into depositing digital assets. The specific threat type involves fraudulent representation of a gambling brand to facilitate unauthorized transactions or data harvesting, with potential secondary risks including crypto wallet drainers or credential theft. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar frequently associated with high-risk domains. It resolves to IP address 104.21.76.105 and is currently offline, though prior scans show it was active on two security blocklists, including PhishDestroy and OISD. VirusTotal reports 17 out of 95 security vendors flagging the domain as malicious, while Gridinsoft assigns a trust score of 1 out of 100. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and fraudulent sites. AlienVault OTX records the domain in one threat intelligence pulse, further corroborating its malicious classification. Mitigation for this brand impersonation threat requires multi-layered defenses. Network administrators should implement DNS-level blocking for gusewin.com and its associated IP 104.21.76.105, while monitoring for related domains registered through the same registrar. Endpoint protection systems should be configured to detect and prevent access to domains with similar naming patterns (e.g., *-win.com) or those impersonating gambling platforms. Users should be educated to verify domain authenticity through official brand channels and avoid interacting with unsolicited gambling offers, particularly those promoting crypto deposits. Organizations processing cryptocurrency transactions should implement additional verification steps for domains created within the last 12 months, given the prevalence of newly registered domains in fraud campaigns.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
6 threat alerts
OTX references
URLScan
URLScan
Gridinsoft
1/100
Chứng chỉ TLS
Let's Encrypt
Tuổi
3 mo
Trạng thái ghi nhận
Có thể truy cập · hạn chế quyền truy cập 403
PhishDestroy
Danh sách hủy bỏ
Đã liệt kê
Reports Sent
2
Phạm vi dữ liệu13 recorded checks
VirusTotal 4 / 91 URLQuery 6 threat-system alerts PhishStats chưa được kiểm tra OTX 1 community reference CF Radar scan completed URLScan capture báo cáo được lưu trữ URLScan verdict Phân tích hoàn tất Chặn DNS chưa được kiểm tra TLS valid certificate, 61d WHOIS 3 mo old Ảnh chụp màn hình 2 captures · 2 sources Chuỗi chuyển hướng không được thăm dò Gridinsoft 1/100
Tín hiệu bảo mật
GS Gridinsoft Analysis 1 / 100
5 0 2 3 29
Tình báo an ninh mạng Registrar context
Threat Detection Systems 6 alerts
Detection System Indicator Verdict Alert
OpenDNS pazewin.com phishing Phishing Block
DNS4EU pazewin.com malicious Sinkholed
Hagezi Threat Feed pazewin.com malicious Sinkholed
OpenDNS gusewin.com phishing Phishing Block
Hagezi Threat Feed gusewin.com malicious Sinkholed
DNS4EU gusewin.com malicious Sinkholed
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Pipeline ứng phó với các mối đe dọa

Khám phá
Checks
Reports
sẵn có
15/16
Initial Abuse Report (#1)
Sent to 3 abuse contacts at Fewmoretaps OU d/b/a Trustname.com with forensic evidence
abuse@trustname.comabuse@verisign-grs.comcompliance@icann.org
11/05/2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@trustname.comabuse@verisign-grs.comcompliance@icann.org
13/05/2026
2 Reports Filed
2 report records were stored over 90 days; current observed status: Có thể truy cập · hạn chế quyền truy cập

Trạng thái trong danh sách chặn công khai

Bản chụp đã lưu

Tiêu đề trang
Pazewin: Most Popular Online Crypto Casino Based on Blockchain
Chứng chỉ TLS
Valid transport encryption · Được cấp bởi Let's Encrypt · valid for 61 days

Thông tin về tên miền

Tên miền
URLScan Verdict Phân tích hoàn tất score 0 report ↗
Máy chủ / ASN cast-sec · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Danh tiếng của Edge-IP không được quy cho tên miền này.
Nhà đăng ký Fewmoretaps OU d/b/a T… BY(BY) PhishDestroy Investigation
Địa chỉ IP 104.21.76.105 CDN
Vị tríCA Toronto, CA
MạngAS13335 · Cloudflare, Inc.
IP gốc được ẩn sau proxy CDN. Kết quả IP đảo ngược cho địa chỉ biên chứa các đối tượng thuê không liên quan; việc tìm kiếm nguồn gốc yêu cầu dữ liệu DNS thụ động hoặc tính minh bạch của chứng chỉ.
Đăng kýĐược tạo 28/04/2026 (102d)
Trạng thái HTTP403 Forbidden
Elapsed Since First Report 69 days
Nội dung được tính Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Có thể truy cập · hạn chế quyền truy cập.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Nội dung mỗi báo cáo chứa Hồ sơ báo cáo gửi đi được lưu trữ có thể tham chiếu bằng chứng có sẵn tại thời điểm đó, chẳng hạn như phán quyết của nhà cung cấp, dữ liệu đăng ký, chi tiết lưu trữ, phân loại hoặc ảnh chụp màn hình. Trang này không suy ra tải trọng chính xác được phân phối, biên nhận, xác nhận hoặc hành động của người nhận.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
Lần đầu tiên được phát hiện11/05/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Máy chủ tênleonard.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 30/03/2026scanned 28/04/2026
Case ID
ICANN OVERSIGHT

Bối cảnh công nhận và RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Việc công nhận là một hợp đồng, không phải con dấu bảo đảm an toàn. Xác minh các khoản phí của ICANN Đọc RAA §3.18 PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft Không có nội dung nào được tự động gửi.
Lịch sử báo cáo lạm dụng · 2 stored reports over 2 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
2 abuse reports filed over 90 days — latest observed status: Có thể truy cập · hạn chế quyền truy cập
The records name Fewmoretaps OU d/b/a Trustname.com as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
2
reports
90
days
ICANN CC
  1. Report #1 ICANN CC May 11, 2026 · 03:11 UTC
    ESCALATION #1 (0h active): Phishing - gusewin[.]com
    abuse@trustname.com abuse@verisign-grs.com compliance@icann.org
  2. Report #2 ICANN CC 45h still active May 13, 2026 · 00:58 UTC
    ESCALATION #2 (45h active): Phishing - gusewin[.]com
    abuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Công nghệ · 1 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com Độ tin cậy 100%
Detected via Cloudflare Radar · Wappalyzer engine
Báo cáo tên miền này Gửi bằng chứng và góp phần bảo vệ người khác

Phân tích của VirusTotal

4 / Nhà cung cấp bảo mật 91 đã gắn cờ miền này
View on VT
Last analyzed
alphaMountain.ai
Chong Lua Dao
CyRadar
Forcepoint ThreatSeeker
Phân tích hiệu suất trang

Google PageSpeed Insights — mobile performance audit of gusewin.com · checked Jun 26, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.82s
Largest Contentful Paint
CLS
0.019
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.76s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.

Europol
Tìm kênh báo cáo chính thức cho quốc gia EU của bạn
National police directory
Hãy cảnh giác với những kẻ lừa đảo lợi dụng việc phục hồi dữ liệu! Tội phạm có thể liên hệ lại với nạn nhân trong khi giả làm điều tra viên, luật sư hoặc nhân viên phục hồi. Không trả phí trả trước hoặc chia sẻ thông tin đăng nhập. Tìm hiểu thêm về gian lận trong quá trình phục hồi →

Hãy báo cáo với chính quyền địa phương

Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.

Danh mục 97 quốc gia
Bản nháp có sự hỗ trợ của AI - chi tiết sự cố được nhà cung cấp AI xử lý Hãy tự mình xem xét và gửi nó
Nhúng báo cáo nàyRead-only HTML widget
HTML · IFRAME

Nhúng báo cáo này

Hãy chia sẻ thông tin tình báo về mối đe dọa này trên trang web hoặc blog của bạn

embed.html
<iframe
  src="https://phishdestroy.io/vi/embed/domain/gusewin.com"
  title="PhishDestroy threat report for gusewin.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Một lá thư cảm ơn vô cùng chân thành

Trình tạo bản nháp châm biếm

Người nhận
Bối cảnh khoản phí

Bản nháp châm biếm. Các khoản phí là số liệu ước tính; không khẳng định chúng được quy chính xác cho tên miền này.