doneld-cvv[.]at
“Doland CC - Donald Trump CVV - Login”
Stored observation
Observed title contrast
Evidence Summary
Analysis indicates that the domain doneld-cvv.at is an active credential phishing site targeting payment card information, as evidenced by its page title 'Doland CC - Donald Trump CVV - Login' and classification as a credential phishing scam. The domain resolves to IP address 172.67.143.108, hosted on Cloudflare's infrastructure (AS13335) in the United States. Front-end technologies include Bootstrap, GSAP, Select2, Moment.js, jQuery, and Cloudflare Browser Insights, suggesting a structured phishing kit rather than a hastily assembled page. The site presents a valid SSL certificate issued by Google Trust Services (WE1), which may reduce user suspicion during initial access. Detection data reveals limited but consistent flagging: Gridinsoft assigns a trust score of 0/100, and the domain appears on one security blocklist, specifically PhishDestroy. VirusTotal reports five detections from 91 vendors, indicating moderate but not universal recognition of the threat. The site remains operational as of July 12, 2026, returning an HTTP 200 status code. Defenders should prioritize blocking the domain and its resolving IP at network and endpoint layers. The use of Cloudflare complicates takedown efforts, but registrar-level reporting (via nic.at) may facilitate disruption. Given the explicit targeting of payment card data in the page title, monitoring for related credential submissions or secondary domains using similar naming conventions ('Doland CC', 'Trump CVV') is recommended. The exact phishing kit in use has not been identified, and further analysis of the site's backend or submission mechanisms could clarify its sophistication and potential links to broader campaigns.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
Technologies
8 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of doneld-cvv.at · checked Jun 26, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive