duckystore.click
Appeared in the .click zone on Wednesday, September 30, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
This is not a Telegram phish. It is the operator's own admin panel, with an 'Admin Key' login, for a Telegram bot that sells 'Locket Gold' premium activations at 25.000đ per use through an 'upstream API' and a TestFlight workaround, with Pay2S auto-bank top-ups and reseller (CTV) management. That fits gray-market resale of the Locket app's paid subscription (piracy) rather than credential harvesting of a brand.
Page impersonates a Telegram Bot admin panel with a login form requesting an 'Admin Key' that posts to itself. The title claims 'Quản Trị Telegram Bot' (Telegram Bot Management), the page displays Telegram branding and UI patterns, and the form has no legitimate purpose other than capturing credentials from users who believe they are accessing a real Telegram administration interface. The operator contact via Telegram (t.me) and sealed-room form architecture confirm phishing intent.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Wednesday, September 30, 2026

Same data as JSON: /api/zone/domain/duckystore.click. This page is not indexed by search engines and does not link to the site it describes.