MALICIOUS — CRITICAL
donked[.]cc
12 of 92 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 12/92
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
donked.cc — Контент недоступний (HTTP 502). Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 12/92 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker); URLQuery 3 alerts; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
donked.cc is classified critical with an evidence score of 100/100. 12 of 92 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 18 May 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, hosted on 172.67.142.97 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 24 May 2026.
Stored generated summary (templated)openai · 08.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain poses a high risk as a brand impersonation threat, specifically targeting Base with a fake crypto casino called Donked. The site was designed to deceive users into believing it was a legitimate blockchain-based gambling platform, but it was actually a malicious attempt to steal funds or credentials.
PhishDestroy identified donked.cc through multiple indicators: it resolves to IP 172.67.142.97, was registered on May 18, 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED, and has an SSL certificate from Google Trust Services (WE1). VirusTotal flagged it with 12 out of 95 security vendors marking it as malicious, and it appears on 3 security blocklists. AlienVault OTX also reported it in one threat intelligence pulse. The site is now offline, but the domain remains a risk.
Users should avoid visiting donked.cc or any related links. If you have already interacted with the site, change your passwords immediately and monitor your accounts for unauthorized transactions. Report any suspicious activity to relevant authorities and consider using a trusted security solution to scan your devices.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | donked.cc |
phishing | Phishing Block |
| Hagezi Threat Feed | donked.cc |
malicious | Sinkholed |
| DNS4EU | donked.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Latest Classified Outcome 2026-08-09 03:52:22 UTC
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-1779592812-donked.cc Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.