# donate-google-com.review.software-moling.com — MALICIOUS > PhishDestroy identifies donate-google-com.review.software-moling.com as an active crypto drainer impersonating Google for fake donations. ## Summary PhishDestroy identifies the domain donate-google-com.review.software-moling.com as an active crypto drainer kit impersonating Google, designed to trick users into donating cryptocurrency under false pretenses. The domain closely mimics Google's branding to exploit trust and facilitate fund misappropriation. This campaign leverages social engineering tactics, specifically targeting users searching for charitable donation opportunities linked to the Google brand. Technical indicators confirm elevated risk: the domain exhibits a VirusTotal detection score of 9/95 security vendors, resolves to IP 168.119.114.11, and was registered through GoDaddy.com, LLC on August 13, 2020. The domain holds a valid Let's Encrypt SSL certificate and is flagged by Google Safe Browsing under the category SOCIAL_ENGINEERING. These attributes collectively signal an ongoing threat operation aimed at financial exploitation through fraudulent donation schemes. The campaign remains active and poses a significant risk to unwary users. PhishDestroy advises immediate avoidance and blacklisting of this domain. Users should verify donation platforms via official Google channels and utilize security tools to block access. While mitigation actions are in place, including Safe Browsing blocks, the longevity of the domain since 2020 suggests persistent threat actor evasion tactics. Remaining risk is elevated due to ongoing accessibility and continued abuse of brand trust. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: Google ## Domain Intelligence - Registered: 2020-08-13 12:39:23 - Registrar: GoDaddy.com, LLC - IP: 168.119.114.11 ## Detection Status - VirusTotal: 9 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c13ed25f-b15a-4ff8-80db-049f1ab9145d - PhishDestroy: https://phishdestroy.io/domain/donate-google-com.review.software-moling.com/ - LLM endpoint: https://phishdestroy.io/domain/donate-google-com.review.software-moling.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/donate-google-com.review.software-moling.com/ Last updated: 2026-03-30