Highscore 46 · flagged Wednesday, September 30, 2026

duckystore.click

Appeared in the .click zone on Wednesday, September 30, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: click
+8
brand in page title, not in the name
matched: telegram
+20
form on a brand-styled page
matched: has_form
+18
Registrar
iNET SOFTWARE COMPANY LIMITED
Nameserver provider
Nameservers
laocai.vclouddns.com, sapa.vclouddns.com
First-day state
active website
HTTP status
200
Page title
Quản Trị Telegram Bot Locket Gold
Has a form
yes
Brand echoed
—

Model opinions

Second opinionlooks like abuseconfidence 60%· claude-opus-5-5

This is not a Telegram phish. It is the operator's own admin panel, with an 'Admin Key' login, for a Telegram bot that sells 'Locket Gold' premium activations at 25.000đ per use through an 'upstream API' and a TestFlight workaround, with Pay2S auto-bank top-ups and reseller (CTV) management. That fits gray-market resale of the Locket app's paid subscription (piracy) rather than credential harvesting of a brand.

First passlooks like phishingtarget: Telegramconfidence 95%· claude-haiku-4-5

Page impersonates a Telegram Bot admin panel with a login form requesting an 'Admin Key' that posts to itself. The title claims 'Quản Trị Telegram Bot' (Telegram Bot Management), the page displays Telegram branding and UI patterns, and the form has no legitimate purpose other than capturing credentials from users who believe they are accessing a real Telegram administration interface. The operator contact via Telegram (t.me) and sealed-room form architecture confirm phishing intent.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Wednesday, September 30, 2026

Screenshot of duckystore.click taken by the zone census on 2026-09-30

Same data as JSON: /api/zone/domain/duckystore.click. This page is not indexed by search engines and does not link to the site it describes.