# PhishDestroy threat dossier — play.monkeycasino.com ================================================================ Fetched: 2026-08-01 05:58:13 UTC Canonical: https://phishdestroy.io/domain/play.monkeycasino.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 84/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: ["may.ns.cloudflare.com", "noel.ns.cloudflare.com"] Page title: MonkeyCasino HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-12 Status: INVALID chain Fingerprint: 9abdeac039a54eae6b2cf1abee62e9d44c5ee0d6eaf5be8244a08d770813675d Subject Alternative Names (related infrastructure — often same operator): - monkeycasino.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 19:43:08 UTC (by PhishDestroy tracker) Last verified: 2026-08-01 04:20:30 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 19:44:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] play.monkeycasino.com Generic Phishing Alert play.monkeycasino.com was observed delivering a generic phishing campaign as indicated by the threat classification. The domain is registered through Cloudflare, Inc. and uses Cloudflare name servers (may.ns.cloudflare.com, noel.ns.cloudflare.com), suggesting the hosting infrastructure is provided by Cloudflare's edge network. VirusTotal reports that the domain has been scanned by 91 security vendors; none of the vendors raised a detection at the time of analysis. The domain appears on a single external blocklist and is currently blocked by the PhishDestroy filtering service, providing some level of community‑based mitigation. An HTTP GET request to the root URL returns status code 200, confirming that a web service is actively responding. No additional metadata such as page title, SSL certificate details, or observed content has been disclosed, leaving the exact phishing lure and target brand unknown. The lack of detections does not imply benign intent, and the presence on a blocklist indicates that other observers have deemed the site malicious. Defenders should add play.monkeycasino.com to network‑level deny lists, enforce URL filtering, and monitor DNS queries for any resolution to Cloudflare IP ranges associated with this domain. Continuous re‑scanning with multiple AV engines is recommended, as threat actors may modify payloads or hosting. Until further content analysis is available, the domain should be treated as high‑risk for credential harvesting or other phishing‑related abuse. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4e548d06a6f3be1355bc5963706ef6e3 TLS cert SHA-256: 9abdeac039a54eae6b2cf1abee62e9d44c5ee0d6eaf5be8244a08d770813675d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/play.monkeycasino.com/ JSON API: https://api.destroy.tools/v1/check?domain=play.monkeycasino.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,248 domains (91,191 alive under monitoring, 27,325 confirmed neutralized). Site: https://phishdestroy.io