MALICIOUS — HIGH
Проверка домена donate-pay.help на фишинг и безопасность
donate-pay[.]
Security analysis of donate-pay.help covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
- VirusTotal
- 4/94
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
donate-pay.help — Контент недоступен (HTTP 502). Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 4/94 (Ermes, LevelBlue); PhishDestroy score 65/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
Analysis indicates that the domain donate-pay.help was registered on March 17 2026 through Global Domain Group LLC and is currently resolved to the Cloudflare‑provided address 188.114.97.3, which maps to a Cloudflare, Inc. presence in Canada. The domain is served behind Cloudflare’s edge network, as evidenced by the presence of Cloudflare Browser Insights and HTTP/3 support, and it presents a valid Let’s Encrypt certificate (issuer E7). DNS resolution uses the nameservers romina.ns.cloudflare.com and vasilii.ns.cloudflare.com. Reputation data shows a Gridinsoft trust score of 0 out of 100 and inclusion on a single security blocklist, with PhishDestroy explicitly listing the domain as blocked.
VirusTotal scans returned four positive detections out of ninety‑four vendors, confirming that multiple security products have flagged the site. The page title returned by the server is simply “donate-pay.help”, and no further content has been captured because the service has been taken offline. The combination of a recent registration, low trust score, blocklist presence, and multiple vendor detections aligns with the elevated risk rating assigned to the domain.
Defenders should continue to block the domain and its associated IP address at perimeter firewalls and proxy filters, enforce DNS‑based deny‑list rules for the identified nameservers, and monitor for any re‑hosting attempts that may arise from the same Cloudflare account. Because the site is currently offline, future activity may be observed if the attacker reactivates the domain; continuous telemetry on DNS queries and TLS handshakes is recommended. Organizations should also verify that internal URL filtering solutions incorporate the current blocklist entries to prevent accidental access should the domain become reachable again.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of donate-pay.help · checked Mar 21, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260321-F326B0 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.