MALICIOUS — HIGH
donate-pay[.]help
Security analysis of donate-pay.help covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
- VirusTotal
- 4/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
donate-pay.help — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 4/94 (Ermes, LevelBlue); PhishDestroy score 65/100. Kayıt kuruluşu: Global Domain Group.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Is donate-pay.help a Phishing Site?
Security analysis of donate-pay.help covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
Analysis indicates that the domain donate-pay.help was registered on March 17 2026 through Global Domain Group LLC and is currently resolved to the Cloudflare‑provided address 188.114.97.3, which maps to a Cloudflare, Inc. presence in Canada. The domain is served behind Cloudflare’s edge network, as evidenced by the presence of Cloudflare Browser Insights and HTTP/3 support, and it presents a valid Let’s Encrypt certificate (issuer E7). DNS resolution uses the nameservers romina.ns.cloudflare.com and vasilii.ns.cloudflare.com. Reputation data shows a Gridinsoft trust score of 0 out of 100 and inclusion on a single security blocklist, with PhishDestroy explicitly listing the domain as blocked.
VirusTotal scans returned four positive detections out of ninety‑four vendors, confirming that multiple security products have flagged the site. The page title returned by the server is simply “donate-pay.help”, and no further content has been captured because the service has been taken offline. The combination of a recent registration, low trust score, blocklist presence, and multiple vendor detections aligns with the elevated risk rating assigned to the domain.
Defenders should continue to block the domain and its associated IP address at perimeter firewalls and proxy filters, enforce DNS‑based deny‑list rules for the identified nameservers, and monitor for any re‑hosting attempts that may arise from the same Cloudflare account. Because the site is currently offline, future activity may be observed if the attacker reactivates the domain; continuous telemetry on DNS queries and TLS handshakes is recommended. Organizations should also verify that internal URL filtering solutions incorporate the current blocklist entries to prevent accidental access should the domain become reachable again.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of donate-pay.help · checked Mar 21, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260321-F326B0 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.