Security Scan Report: winnernet.net

Redirected to:
https://www.winnernet.net/
Site favicon
Submitted: Sep 16, 2026, 4:47:30 PMCompleted: Sep 16, 2026, 4:47:52 PMpubliccompleted

This website contacted 25 IPs in 3 countries across 24 domains to perform 55 HTTP transactions. The main domain is winnernet.net and was registered 6 years ago.

Submitted URL: https://winnernet.net

Effective URL:

https://www.winnernet.net/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Compromised aging casino blog now serving ClearFake/EtherHiding malware: 19 CRITICAL IDS EtherHiding exfil alerts, blockchain RPC C2, obfuscated JS, and a fake-CAPTCHA trick pushing PowerShell execution.

Risk Factors (5)
Serves ClearFake/EtherHiding malware via injected blockchain-based exfiltration
ClickFix-style fake CAPTCHA luring users to paste and execute commands in PowerShell
Heavy obfuscation (eval/Function/encoding) on a simple content page
Blockchain RPC connections used as covert C2 channel
Multiple independent threat-intel feeds flag associated malware infrastructure
Domain age information unavailable

Details

Page Title

WinnerNet welcomes the BIGGEST winners around! - Welcome to winner net

Scan Type

public

Domain Name Analysis

The domain name 'winnernet.net' uses the network infrastructure generic top-level domain (.net) while skipping any subdomain. The core label 'winnernet' covers 9 characters with 3 vowels and six consonants. Tokenizing the label suggests 2 words: winner, net. Median word length comes out to 4.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://winnernet.net

Page Load Overview

1.69s
Total Load Time
1.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,742 chars
Detector Agreement:100%

Website Classification

Primary Category

gambling betting99% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

gambling betting
99%
entertainment media
97%
cryptocurrency blockchain
54%
corporate
35%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7167.99.206.20Slough, England, United Kingdom
AS14061DigitalOcean, LLC
2142.251.14.95Google · CDNUnited States
AS15169Google LLC
2104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2192.178.183.94Google · CDNUnited States
AS15169Google LLC
215.197.152.159Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
234.111.175.102Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.142.245Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
215.197.198.189Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5525--

Detected Technologies6

100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T107928672E19444367F1F87EE81D1B328E558A608DE06ABA5B0F43158C9A86FB10FB71D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:uHXEUc5O/r2WdNJ6Ih7a4r/ZdSZUaAhHkWmN:uHNc5vWDZdypa9u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:19791:izQkGLE7QAZARQnEgNQEqeGIFpiAkYM+5AXBDoYCtAgNAAZA4JFcNw8AUGW0AEZJigwAEZECYAMJSBBodbIKgJryiZCtCFPB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fffffffeffc7c7c7
Perceptual Hash:b2cd321ccd32ccc7
Difference Hash:d8e8d8a4708d8d8d
Wavelet Hash:3c3c5cfcfcc4c444
Color Hash:#d22d93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data