MALICIOUS — CRITICAL
pokoplay[.]com
14 of 93 security engines flagged the domain; the latest stored check returned HTTP 403.
- VirusTotal
- 14/93
- Blocklists
- No stored match
- 可用性
- 可达 · 访问受限 · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 6 outgoing records; the latest is dated . The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
pokoplay.com — 可达 · 访问受限 (HTTP 403). 品牌冒充:Google; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Ermes); URLQuery 3 alerts; PhishDestroy score 97/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Digest
pokoplay.com is classified critical with an evidence score of 97/100. 14 of 93 security engines flagged the domain. Registered 21 Feb 2026 via Tucows Domains Inc., hosted on 142.251.208.4 (GOOGLE - Google LLC, US, DE). The latest stored check on 9 Aug 2026 returned HTTP 403 and includes a capture. 6 outgoing abuse reports are recorded, most recently on 8 Feb 2026.
Stored generated summary (templated)cerebras · 2026年7月23日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of pokoplay.com shows that the domain was registered on 21 February 2026 through Tucows Domains Inc. and is currently listed as offline. The authoritative name servers are kia.ns.cloudflare.com and tadeo.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. DNS resolution points to IP address 142.251.208.4, an address owned by Google LLC (AS15169) located in Germany. Despite the legitimate hosting origin, the site is flagged for brand impersonation of Google; the page title returned by the server is “Google Chrome – den schnellen und sicheren Browser von Google jetzt herunterladen”, matching the targeted brand.
HTTP requests to the host return a 403 status code, suggesting that the content is not publicly accessible at the time of testing. The domain appears on one security blocklist and is blocked by PhishDestroy. VirusTotal analysis records 14 of 93 scanning engines labeling the domain as malicious. The SSL certificate is identified as “WE1”, and the observed phishing kit is classified as a Gambler Scam, while the overall scam type is recorded as a Crypto Scam.
These indicators collectively point to a credential‑stealing or crypto‑draining campaign that leverages a trusted‑looking Google Chrome download page to lure victims. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑activation of the IP address, and add the associated IP range to reputation lists. Given the use of Cloudflare infrastructure, future iterations may employ new subdomains, so ongoing surveillance of newly registered domains that resolve to the same IP or share the same name‑server pair is recommended. Incident response teams should also consider correlating logs for attempts to access the German‑language Chrome download page, as such traffic may indicate targeted phishing attempts.
数据覆盖范围13 recorded checks
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | pokoplay.com |
phishing | Phishing Block |
| Hagezi Threat Feed | pokoplay.com |
malicious | Sinkholed |
| DNS4EU | pokoplay.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
滥用举报历史 · 6 stored reports over 105 days · click to expand
-
Report #1 Escalation 342h still active Feb 8, 2026 · 18:32 UTCESCALATION #2 (342h active): Phishing - pokoplay[.]comdomainabuse@tucows.com
-
Report #2 ICANN CC 925h still active Mar 5, 2026 · 01:30 UTCESCALATION #3 (925h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 958h still active Mar 6, 2026 · 11:12 UTCESCALATION #4 (958h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1995h still active Apr 18, 2026 · 18:51 UTCESCALATION #5 (1995h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 2393h still active May 5, 2026 · 08:56 UTCESCALATION #6 (2393h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #7 ICANN CC 2847h still active May 24, 2026 · 06:32 UTCESCALATION #7 (2847h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
VirusTotal 分析
证据与外部报告Independent lookups and source reports
PD-1770575484-pokoplay.com Recipient: domainabuse@tucows.com Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。