nustwin.com scores 1 out of 100, rated High Risk. 0 regulator warnings, 14 antivirus detections. Last scanned May 11, 2026. Source: https://nustwin.com
nustwin.com
nustwin.com: fake crypto casino exposed
High Risk01/ 100
0-2425-4445-6970-8485-100
Think you may have lost money to this site?
Tell us what happened and get free advice on your case. It is confidential.
The site
What this site
actually is.
Page capture
Screenshot unavailable
Identity
- IP
- 172.67.186.7
- ASN
- AS13335
- Country
- United States

- Domain age
- 8 days
- Registrar
- Fewmoretaps OU d/b/a Trustname.com
- Server
- cloudflare

- Hosting
- Cloudflare, Inc.

- Tech detected
- 3
The verdict
The score is not
an opinion.
Every domain starts at 100. 4 scoring chains fired against nustwin.com, and every one of them is listed below with the tier it reached. It is a measurement, not a ruling on whether the business is legitimate.
Trust Score: the full methodology and every weightTriggered findings
4- Antivirus Tier 4
- Blacklists Tier 1
- Scam Farm Tier 4
- Domain Age Tier 5
The record
How it got there,
and where it sits.
Signal profile data
- Maturity: 1 out of 100. 8 days old
- AV clarity: 0 out of 100. 14 of 93 engines flag it
- Regulators: 100 out of 100. No regulator warnings
- Network: 6 out of 100. Linked to 375 domains
- Blacklist: 70 out of 100. Listed on 1 feed
- Trust zone: 74 out of 100. .com top-level domain
- Infra: 60 out of 100. Valid SSL · 3 tech detected
- Hosting: 75 out of 100. Hosted in US
Domain history
Recorded scans: May 11, 2026
Score history data
| Date (UTC) | Score | Verdict |
|---|---|---|
| May 11, 2026 | 1/100 | High Risk |
- MAY 32027Domain expiresWHOISDomain nustwin.com is set to expire.
- AUG 12026SSL certificate expiresSSL CheckSSL certificate will expire.
- MAY 112026Scam network detectedThreat GraphLinked to 375 domains in a known scam network.
- MAY 112026Listed on cloudflare phishingBlacklistnustwin.com was flagged by cloudflare phishing as of this scan.
- MAY 112026Flagged by VirusTotalVirusTotalFlagged by 14 engines as malicious on VirusTotal.
- MAY 112026First scansnyferTrust score 1 out of 100.
- MAY 32026Domain updatedWHOISnustwin.com WHOIS record was updated.
- MAY 32026Domain createdWHOISDomain nustwin.com was registered.
- MAY 32026SSL certificate issuedSSL CheckSSL certificate issued by Let's Encrypt.
Signals
We are not the first
to say it.
Antivirus engines
BitDefenderphishing
Fortinetphishing
G-Dataphishing
Kasperskyphishing
Sophosmalware
VIPREmalware
Phishing authorities
Chong Lua Daomalicious
CRDFmalicious
Netcraftmalicious
Blacklists
- Cloudflare Phishing · PhishingCloudflare listed
Security vendors
ADMINUSLabsmalicious
alphaMountain.aiphishing
CyRadarphishing
Forcepoint ThreatSeekerphishing
Lionicphishing
Connections
One domain is never
just one domain.
Shared signals
- Favicon #52favicon_hash / 68 domains
Cluster map
Connected domain data (200)
- nustwin.com
- cashrewardgo.com
- jaupux.com
- faufax.com
- wonkawin.com
- veyro.cc
- palowex.com
- vyroget152.to
- tusewin.cc
- dexwin.cc
- vitewin.cc
- sagonex.com
- faowox.com
- fasowin.com
- nugamb.at
- lunior.vip
- xmagex.com
- kasewin.at
- kastwin150.pro
- soawin.com
- xgameon.com
- cribwex.com
- doahux.com
- zeavex.com
- voxocas.com
- hasobin.com
- hasobet.com
- serowin.com
- bevexo.cc
- tefwex.com
- betaras.com
- maxbetwin.cc
- mugamb.cc
- husewin.cc
- alpha-play.cc
- feastwin.com
- exgamb.cc
- olympus-games.net
- spinw.cc
- wildsatz.com
- xmaxe.bet
- beucux.com
- reidax.com
- vasewin.at
- gambinx.com
- foldwin.com
- cleangamb.com
- fatecas.com
- vyroso.win
- wasobin.com
- besobin.com
- ponzobet.com
- eegox.com
- nesvex.com
- gerspin.com
- muzewin.com
- aspin.cc
- blexbet.com
- veivex.com
- vexora.cc
- nensen.cc
- casvax.com
- vinewin.cc
- spacexplay.com
- winkai.cc
- sorax.pro
- cusewin.cc
- jetowex.com
- ponegex.com
- wincase152.cc
- hurowin.com
- playgrand.cc
- theace.bet
- win777gold.com
- ceudex.com
- zumowex.com
- fuxowin.com
- buzawin.com
- noergamb.com
- tosowin.com
- merowin.com
- nesobin.com
- kasowin.com
- soakwin.com
- fuzawin.com
- nedkas.com
- caorax.com
- mixwex.com
- menty.sbs
- boferex.com
- luxolplays.com
- upgamb.cc
- winnerslive.at
- pvcas.com
- egamb.cc
- vaivax.com
- wildgame.cc
- icespin.net
- ezewex.com
- kilowin.com
- gaxspace.com
- geobet.cc
- xwins.cc
- durcas.com
- tustwin.com
- guonex.com
- layercas.com
- coawox.com
- bosawin.com
- nuefax.com
- teuzux.com
- fearwin.com
- tuzawin.com
- vyromex.com
- musksino.cc
- foterex.com
- peowax.com
- suwau.com
- goxeu.com
- betrawin.com
- belazbet.com
- xhodes.com
- hozerex.com
- toferex.com
- heidax.com
- vezwex.com
- rollchain.world
- eloxbet.com
- minagex.com
- nerogex.com
- gamesofbeast.com
- deocox.com
- roonbet.com
- voltera.vip
- foapux.com
- zexonas.com
- fezorex.com
- nelarion.com
- xopeu.com
- jeybet.com
- nordvik.vip
- shadowflux.vip
- bastwin.com
- cofixplay.com
- zuakex.com
- wolvex.cc
- binkwin.com
- seuvox.com
- trywand.cc
- vyroso777.to
- jelowex.com
- lewycon.cc
- jastwin.com
- presidental.casino
- furydex.com
- neidax.com
- bnbit.win
- betova.io
- nizwex.com
- goferex.com
- onegamb.at
- pezwex.com
- pragmaslot.at
- elonx.life
- stake-roll.com
- playempirex.com
- beivax.com
- elmunix.com
- draketake.com
- zazawin.com
- gaopex.com
- kazewin.com
- rolspace.top
- marsodex.com
- sapety.com
- dezoxplay.com
- wezogex.com
- elonxbet.com
- moawax.com
- baxmot.com
- elbeaston.com
- jackragame.com
- reakox.com
- moekex.com
- suzewin.com
- kaorax.com
- spacegax.com
- boacux.com
- tilodex.com
- mrbet.win
- 1xjett.com
- xorawin.com
- xesowin.com
- rosawin.com
- caemux.com
- raiwax.com
- diamondcash.live
- gambuxs.com
- betdeal.pro
- kalowex.com
Where it lives
Where it actually
answers from.
Under the page
What the page loads
behind your back.
Page timing
Resources
Network stats
- 11
- total requests
- 931 B
- total bytes
- 2
- failed requests
- 2
- unique domains
- 73%
- third party
- 100%
- https
HTTP transactions
Raw scan data
{
"domain": "nustwin.com",
"scanId": "c5886f24942148fd931f73c25e57f4c4",
"status": "completed",
"indexable": false,
"publicNotice": null,
"completedAt": "2026-05-11T14:32:09.969Z",
"ageDays": 123,
"fresh": false,
"verdict": "dangerous",
"trustScore": 1,
"badges": [
{
"name": "antivirus_tier4",
"chain": "antivirus",
"tier": 4,
"maxTier": 4,
"score": -99,
"description": "Detected by 10+ engines"
},
{
"name": "blacklists_tier1",
"chain": "blacklists",
"tier": 1,
"maxTier": 2,
"score": -38,
"description": "Flagged by 1 blacklist provider (Google Safe Browsing, Cloudflare, etc.)"
},
{
"name": "scam_farm_tier4",
"chain": "scam_farm",
"tier": 4,
"maxTier": 4,
"score": -12,
"description": "Shares code with 10+ domains"
},
{
"name": "domain_age_tier5",
"chain": "domain_age",
"tier": 5,
"maxTier": 5,
"score": -3,
"description": "Domain < 30 days"
}
],
"reachable": true,
"unreachableReason": null,
"category": null,
"categoryReasoning": "Site flagged by Cloudflare as suspected phishing — actual content not accessible",
"regulatorFlagged": false,
"regulators": [],
"contacts": {
"emails": [],
"phones": [],
"addresses": []
},
"technologies": [
{
"name": "Cloudflare",
"category": "cdn"
},
{
"name": "Tailwind CSS",
"category": "css-framework"
},
{
"name": "Cloudflare Turnstile",
"category": "security"
}
],
"antivirus": {
"detections": [
{
"engine": "ADMINUSLabs",
"result": "malicious",
"engineType": "security_vendor"
},
{
"engine": "alphaMountain.ai",
"result": "phishing",
"engineType": "security_vendor"
},
{
"engine": "BitDefender",
"result": "phishing",
"engineType": "antivirus"
},
{
"engine": "Chong Lua Dao",
"result": "malicious",
"engineType": "phishing_authority"
},
{
"engine": "CRDF",
"result": "malicious",
"engineType": "phishing_authority"
},
{
"engine": "CyRadar",
"result": "phishing",
"engineType": "security_vendor"
},
{
"engine": "Forcepoint ThreatSeeker",
"result": "phishing",
"engineType": "security_vendor"
},
{
"engine": "Fortinet",
"result": "phishing",
"engineType": "antivirus"
},
{
"engine": "G-Data",
"result": "phishing",
"engineType": "antivirus"
},
{
"engine": "Kaspersky",
"result": "phishing",
"engineType": "antivirus"
},
{
"engine": "Lionic",
"result": "phishing",
"engineType": "security_vendor"
},
{
"engine": "Netcraft",
"result": "malicious",
"engineType": "phishing_authority"
},
{
"engine": "Sophos",
"result": "malware",
"engineType": "antivirus"
},
{
"engine": "VIPRE",
"result": "malware",
"engineType": "antivirus"
}
],
"enginesTotal": 93,
"permalink": "https://www.virustotal.com/gui/url/aHR0cHM6Ly9udXN0d2luLmNvbS8",
"scannedAt": "2026-05-11T14:31:47.536Z"
},
"blacklists": [
{
"provider": "google_safe_browsing",
"flagged": false,
"threats": []
},
{
"provider": "cloudflare_phishing",
"flagged": true,
"threats": [
"PHISHING"
]
}
],
"registration": {
"registrar": "Fewmoretaps OU d/b/a Trustname.com",
"registrarIanaId": "4318",
"createdAt": "2026-05-03T03:11:03.000Z",
"updatedAt": "2026-05-03T03:11:17.000Z",
"expiresAt": "2027-05-03T03:11:03.000Z",
"ageDays": 8,
"ageText": "8d",
"privacyProtected": false,
"nameservers": [
"nelci.ns.cloudflare.com",
"rustam.ns.cloudflare.com"
]
},
"certificate": {
"issuer": "Let's Encrypt",
"validFrom": "2026-05-03T02:15:50.000Z",
"validUntil": "2026-08-01T02:15:49.000Z",
"valid": true,
"protocol": "TLSv1.3"
},
"hosting": {
"ip": "172.67.186.7",
"countryCode": "US",
"countryName": "United States",
"city": "San Francisco",
"provider": "Cloudflare, Inc.",
"asn": 13335,
"serverSoftware": "cloudflare",
"mapImageUrl": null,
"latitude": 37.7621,
"longitude": -122.3971,
"behindCloudflare": true
},
"timing": {
"dnsMs": 1,
"connectMs": 56,
"tlsMs": 34,
"ttfbMs": 31,
"downloadMs": 2,
"domReadyMs": 171,
"loadCompleteMs": 365
},
"resources": [
{
"kind": "images",
"count": 3,
"bytes": 930
},
{
"kind": "scripts",
"count": 2,
"bytes": 0
},
{
"kind": "xhr",
"count": 2,
"bytes": 0
},
{
"kind": "documents",
"count": 2,
"bytes": 0
},
{
"kind": "fetch",
"count": 1,
"bytes": 1
},
{
"kind": "stylesheets",
"count": 1,
"bytes": 0
}
],
"networkStats": {
"totalRequests": 11,
"totalBytes": 931,
"failedRequests": 2,
"uniqueDomains": 2,
"thirdPartyRatio": 0.7273,
"httpsPercentage": 100
},
"cookies": [],
"identity": {
"finalUrl": "https://nustwin.com/",
"brandName": null,
"faviconUrl": "/api/scan/favicon/c5886f24942148fd931f73c25e57f4c4"
},
"telemetry": {
"statusCode": 403,
"durationMs": 23064,
"scraper": "patchright",
"attempts": 1,
"source": "single",
"contentType": "text/html; charset=utf-8"
},
"securityHeaders": [
{
"key": "content_security_policy",
"present": false,
"value": null
},
{
"key": "strict_transport_security",
"present": false,
"value": null
},
{
"key": "x_frame_options",
"present": true,
"value": "SAMEORIGIN"
},
{
"key": "x_content_type_options",
"present": false,
"value": null
},
{
"key": "referrer_policy",
"present": true,
"value": "same-origin"
},
{
"key": "permissions_policy",
"present": false,
"value": null
},
{
"key": "x_xss_protection",
"present": false,
"value": null
},
{
"key": "cross_origin_opener_policy",
"present": false,
"value": null
}
],
"redirects": [],
"transactions": [
{
"url": "https://nustwin.com/",
"method": "GET",
"resourceType": "document",
"statusCode": 403,
"bytes": 0,
"thirdParty": false
},
{
"url": "https://nustwin.com/cdn-cgi/styles/cf.errors.css",
"method": "GET",
"resourceType": "stylesheet",
"statusCode": 200,
"bytes": 0,
"thirdParty": false
},
{
"url": "https://challenges.cloudflare.com/turnstile/v0/api.js",
"method": "GET",
"resourceType": "script",
"statusCode": 302,
"bytes": 0,
"thirdParty": true
},
{
"url": "https://nustwin.com/cdn-cgi/images/icon-exclamation.png?1376755637",
"method": "GET",
"resourceType": "image",
"statusCode": 200,
"bytes": 452,
"thirdParty": false
},
{
"url": "https://challenges.cloudflare.com/turnstile/v0/g/fe6331af5207/api.js",
"method": "GET",
"resourceType": "script",
"statusCode": 200,
"bytes": 0,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/f/ov2/av0/rch/4mndg/0x4AAAAAABDaGKKSGLylJZFA/auto/fbE/new/normal?lang=auto",
"method": "GET",
"resourceType": "document",
"statusCode": 200,
"bytes": 0,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1",
"method": "GET",
"resourceType": "image",
"statusCode": 200,
"bytes": 86,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1394817869:1778506116:Ae5lWhTKxCp5OIY74q8lO0toZeCgpJh96zkU32TYwg8/9fa1e3ac5d68db03/ZJwCbhcCHcpZpDrRvXuXgLyAgt8XLJok0pnJ8w4tNzA-1778509907-1.2.1.1-Kwj66re4cr5wxj2W30Dp7.0LTZ7wRdYeWXjQICgZxvZLm.loULP4NuZP5yqGntyQ",
"method": "POST",
"resourceType": "xhr",
"statusCode": 200,
"bytes": 0,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/9fa1e3ac5d68db03/1778509908238/kRfhuVUXBcnBH2-",
"method": "GET",
"resourceType": "image",
"statusCode": 200,
"bytes": 392,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/9fa1e3ac5d68db03/1778509908239/4dea98d9381d2ac96b3e1f3a084bbf0f7e2d01516665c7c04aa085a922bfb034/M7c5U83-vsEyhoK",
"method": "GET",
"resourceType": "fetch",
"statusCode": 401,
"bytes": 1,
"thirdParty": true
},
{
"url": "https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1394817869:1778506116:Ae5lWhTKxCp5OIY74q8lO0toZeCgpJh96zkU32TYwg8/9fa1e3ac5d68db03/ZJwCbhcCHcpZpDrRvXuXgLyAgt8XLJok0pnJ8w4tNzA-1778509907-1.2.1.1-Kwj66re4cr5wxj2W30Dp7.0LTZ7wRdYeWXjQICgZxvZLm.loULP4NuZP5yqGntyQ",
"method": "POST",
"resourceType": "xhr",
"statusCode": 200,
"bytes": 0,
"thirdParty": true
}
],
"hasCapture": false,
"archive": {},
"networkSize": 349
}From readers
What people who
were there told us.
No reports yet
Be the first to share what happened with this site: a withdrawal that will not process, a refund you never received, an account you can no longer reach. Reports are pre-moderated and anonymous by default.
Submit the first report