fancychicken[.]online
“777 Casino – vegas slots games”
Stored detection
Cloaking alert
- Cloaking type
content_split- Cloaking score
- 4/6
Evidence Summary
This domain, fancychicken.online, is flagged for brand impersonation targeting Facebook, presenting itself as a casino-themed scam page titled '777 Casino – vegas slots games.' The infrastructure appears designed to harvest user credentials under the guise of a legitimate social media login portal, while redirecting victims to fraudulent gambling content. No known drainer kit signatures were identified, but the mismatch between the advertised Facebook branding and the casino page title suggests a dual-purpose phishing and scam operation. Analysis indicates the domain holds a VirusTotal detection score of 1/95 security vendors, was registered through Go Daddy, LLC on July 24, 2025, and resolves to the IP address 104.21.35.191. It is protected by Cloudflare and uses HTTP/3, with an SSL certificate issued by Google Trust Services. The domain appears on one security blocklist and was assigned a Gridinsoft trust score of 0/100, confirming its malicious classification. No Google Safe Browsing (GSB) listing was recorded at the time of assessment. The domain is currently offline, likely due to takedown or suspension following detection by security systems. While the immediate threat has been mitigated, residual risk remains for users who may have interacted with the domain prior to its deactivation. Organizations and individuals are advised to monitor for unauthorized access attempts linked to credentials potentially exposed via this infrastructure. Network-level blocking of the IP 104.21.35.191 and domain-level filtering of fancychicken.online are recommended as proactive defensive measures.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
VirusTotal
2 → 1
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive