Security Scan Report: donutclaim.site

Redirected to: https://donutclaim.site/checkout/packages/add/2748075/single/lstp1tutajfv11h19cl6

Site favicon
Submitted: Jan 18, 2026, 6:49:52 PMCompleted: Jan 18, 2026, 6:51:01 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 1 country across 8 domains to perform 1 HTTP transaction. The main domain is donutclaim.site and was registered NaN years ago.

Submitted URL: https://donutclaim.site/7461115

Effective URL: https://donutclaim.site/checkout/packages/add/2748075/single/lstp1tutajfv11h19cl6Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam: brand‑new domain harvesting Minecraft usernames.

Risk Factors
Newly registered domain (<7 days) with a login form
Brand impersonation on an unranked, brand‑new domain
Credential‑harvesting form (username field) on suspicious domain
Domain age information unavailable

Details

Page Title

Donut SMP | Login

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(51%)

Domain Information

Within the .site top-level domain, 'donutclaim.site' is registered. The second-level label 'donutclaim' is 10 characters long holding four vowels versus six consonants. Tokenizing the label suggests 2 words: donut, claim. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://donutclaim.site/7461115

Page Load Overview

3.20s
Total Load Time
12
HTTP Requests
5
Domains
384 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:188 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software51% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
51%
e-commerce
15%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
618.245.46.78United States
1104.17.25.14United States
1142.251.141.74United States
AS15169GOOGLE
1104.18.28.42United States
AS13335CLOUDFLARENET
113.35.58.2United StatesUnknown
1128.65.223.115United StatesUnknown
1188.114.97.3United States
AS13335CLOUDFLARENET
127--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13093564BAAE311457803AA743BFF77A43A79A013D509CDB83E9C7368CF462D5986274C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:mb4YoF0F/fA2FsQwjFqFiSkFCFzSVPqnUn5CtKk2AIDb0DwH:1l6JA2SQwjI0MQhq8k2AIDb0cH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:93775:xMg4TxASKIqwJJADEIjCwYFJiGEITQAo+DyhYIIHCMXACNIBkzBQo0TCrQZoARt2gBk8GEbBKIkBJ44hJFgQaUx0B2JwAQBL

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0119093d3d0901ff
Perceptual Hash:8a4c3533ce663373
Difference Hash:1131317171591531
Wavelet Hash:1119193d3d3d01ff
Color Hash:#7253ac

Other Hashes

Crop Resistant:1131317171591531

Scan History

Scan history not available

Unable to load historical scan data