Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
riovax[.]win
“Riovax: Most Popular Online Crypto Casino Based on Blockchain”
riovax.win — 隐形 · 可达. 品牌冒充:Genericcrypto; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 8/94 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 2 alerts; URLScan malicious verdict; cloaking observed; PhishDestroy score 78/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
riovax.win has been classified by PhishDestroy as a high-risk crypto drainer domain currently active and targeting cryptocurrency users through fake wallet login pages. The site poses an elevated threat to visitors who may unknowingly enter seed phrases or private keys, resulting in direct asset theft. PhishDestroy strongly advises against accessing this domain or interacting with any linked content, as the risk of financial loss is significant and imminent.
PhishDestroy identifies riovax.win as a crypto drainer with confirmed malicious activity. The domain was created on March 09, 2026, registered through Gname.com Pte. Ltd., and resolves to ASN 13335 at IP address 188.114.96.3 via Cloudflare infrastructure. It has been flagged by 7 of 95 security vendors on VirusTotal and carries low trust scores across multiple reputation engines. The site uses a valid Let's Encrypt SSL certificate, which may lull victims into a false sense of security. Despite its youth—only weeks old—riovax.win exhibits clear indicators of malicious intent, including redirection chains to known crypto drainer infrastructure and cloned wallet interfaces designed to harvest private keys or seed phrases.
To mitigate risk, PhishDestroy recommends users immediately block riovax.win at the network and DNS levels using updated blocklists such as PhishDestroy’s Real-Time Feed. Never enter wallet credentials or seed phrases on any site accessed via this domain or similar shortened URLs. If a wallet login page is suspected to be malicious, verify the domain against PhishDestroy’s latest scan results or cross-check using multiple reputable sources like Etherscan, Lens, or official wallet documentation. Enable hardware wallet signing for all transactions and revoke any previously approved but unauthorized smart contract permissions. Report any interaction with this domain to PhishDestroy’s threat intelligence team to help protect the broader cryptocurrency community.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 3 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of riovax.win · checked Apr 13, 2026
证据与外部报告
PD-20260413-ECFC0F Recipient: complaint@gname.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。