DANGEROUS

Cracked-software site — high malware risk

Modded APK site offering Dragon City with unlimited money and gems, flagged by Gridinsoft and PCrisk.

Security Review

Is dragon-city-1.modcombo.com legit or a scam?

Modded APK site offering Dragon City with unlimited money and gems, flagged by Gridinsoft and PCrisk.

Do this now:Do not download or install any APK from this site. Stick to official app stores for Dragon City and similar games.

This is a modded-APK download site that distributes cracked Android games. Two independent security vendors flag the domain with low trust scores and phishing indicators.

Cross-checked against 9 completed checks 2 raised a concern
dragon-city-1.modcombo.comScanned 1h ago
4/100
Trust score
0 = danger · 100 = safe
DANGEROUS
Score breakdown
Heuristics 37·MT 4
Screenshot of dragon-city-1.modcombo.comSee the live page ↓
Category tags
fake-apkHow sure we are: High
Technical red flags (1)
Cracked APK / Modded App
Warning signals (1)
Scam-network signals (20/100)
Positive signals (5)
Antivirus clearNot on major blacklistsDomain is 6 years oldEncrypted connectionClean server reputation

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

What this means for you

You were probably about to download cracked or 'pre-activated' software.

The 'crack' that unlocks it is one of the most common ways people get infected — often an infostealer or ransomware. No antivirus makes a pirated installer safe.

How this scam works

The trap, step by step

  1. They offer expensive paid software “free”, cracked or pre-activated.

  2. The download includes a “crack” or “keygen” you must run — and are told to disable antivirus for.

  3. That crack is very often the malware itself (your AV was right).

  4. It quietly steals your logins and crypto, or installs a miner in the background.

Recognising the pattern is the best defence — if a site follows these steps, close it and don't enter anything.

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
6 years old
Registered Mar 10, 2020

Website Preview

Visual analysis

We capture a fresh screenshot of the live page and ask a vision model to look for scam visual patterns — fake trust badges, countdown timers, overlay pop-ups, and visual clones of legitimate brands.

85
/ 100
Critical visual risk

Visual red flags detected in the screenshot

The website functions as a repository for modified Android applications, which presents a significant security risk due to the potential for bundled malware or malicious code in the provided APK files.

Visual risk85/100

What our vision model saw

5 signals

Site distributes modified APK files ('Mod APK') for mobile games, a common vector for malware distribution

Promotes 'Unlimited money, gems' which is a common tactic to lure users into downloading potentially harmful software

Uses high-visibility 'Download Now' buttons to encourage immediate interaction

Includes a 'Join our Telegram community' call-to-action, frequently used by mod sites to distribute further malicious payloads

Page layout is consistent with third-party app repositories that bypass official app store security controls

Intelligence

Editorial security brief
Intelligence
High risktrust4/100patternCracked Software — Malware Risk
90%
Confidence
The page promotes a modified Dragon City APK with unlimited in-game currency, a classic lure for malware distribution. Gridinsoft assigns the domain a 10/100 trust score and notes phishing indicators, while PCrisk reports a 40/100 score with three engines flagging the site. The domain is six years old and hosted on Cloudflare, yet the operator hides ownership behind identity-protection services. The site loads multiple language-specific subdomains and external analytics scripts, consistent with a high-volume modded-app farm. No legitimate business registration or contact details appear anywhere on the page. These combined signals outweigh the clean antivirus scan and push the verdict into malicious.
Risk Factors
5
  • Distributes modified Android APKs that commonly bundle malware or stealers.
  • Gridinsoft flags the domain with phishing indicators and a 10/100 trust score.
  • PCrisk reports a 40/100 trust score and three engine detections.
  • No contact email, postal address, or verifiable business registration found.
  • Owner identity hidden behind identity-protection services despite disabled WHOIS privacy.
Positive Signals
3
  • Domain registered 6.4 years ago, reducing the chance of a brand-new scam operation.
  • Hosting IP shows zero abuse reports and a clean reputation score.
  • SSL certificate is valid and issued by Google Trust Services.
Investigation notes

Page Content

The captured page advertises Dragon City Mod APK version 26.9.1 with unlimited money and gems. It includes a prominent Download Now button, a Telegram community link, and a list of top dragons with fabricated stats. No contact email, postal address, or company name is present. The page loads five external modcombo subdomains plus Google Analytics and Cloudflare scripts.

Infrastructure

The site resolves to IP 104.21.71.33 behind Cloudflare. SSL certificate is issued by Google Trust Services and valid for another 49 days. No abuse reports exist for the IP. The domain is registered through NameSilo with privacy protection disabled, yet the owner identity remains hidden. One cross-domain redirect occurs before the final page loads.

Domain History

WHOIS records show registration on 2020-03-10, giving the domain an age of 6.4 years. No prior ownership changes are visible in the provided data. The registrar is NameSilo, LLC.

Web Reputation

Gridinsoft lists the domain with a 10/100 trust score and phishing indicators. PCrisk assigns a 40/100 score and notes that three of 91 engines flagged the site. No positive reviews or business registrations were located. Two scam reports explicitly warn against entering credentials or payment data on the domain.

What this means for you

Downloading the offered APK risks installing malware or unwanted software. The combination of cracked-app distribution, low trust scores, and hidden ownership indicates the site is unsafe.

Recommendation
Do not download or install any APK from this site. Stick to official app stores for Dragon City and similar games.
Editorial assessment
SpecificEvidence-led

Web Research Findings

Independent findings for dragon-city-1.modcombo.com, including public complaints, named review sources, registration records, and look-alike-domain evidence. A missing result is shown as unverified, never converted into a clean bill of health.

Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
2 scam reports
Key findings
5 headline facts from open-web research
  • Modcombo.com is a high-traffic platform that distributes modified (modded) Android APK files, which often include 'unlocked' premium features.
  • Security vendors have flagged the domain with low trust scores (e.g., 10/100) and identified phishing indicators on certain subdomains.
  • While the domain has been registered since 2020, it is frequently associated with risks such as unwanted software, misleading installers, and copyright infringement.
  • The site uses Cloudflare for infrastructure and identity protection services to hide the owner's identity, making it difficult to verify the legitimacy of the operators.
  • Security scans have reported mixed results, with some engines flagging the site for malicious objects or phishing, while others report no threats found.
Scam reports (2)
Direct quotes from public scam databases, forums, and news.
  • Gridinsoftopen

    "Security vendors flag phishing indicators on Modcombo.com. Trust score: 10/100. Do not enter passwords or payment data."

  • PCriskopen

    "Moderate Risk — trust score 40/100, 3/91 engines flagged. ... download portals can sometimes expose visitors to unwanted software, misleading installers, or copyright-related concerns."

Research summary
Editorial synthesis of the sourced facts above
Gridinsoft reports phishing indicators on Modcombo.com with a 10/100 trust score. PCrisk assigns a 40/100 score and notes that download portals can expose visitors to unwanted software or misleading installers.

Domain Timeline

  1. Mar 10, 2020
    Domain registered

    First appeared in WHOIS records — 6.4 years old today.

  2. Jul 23, 2026
    Latest security review — Flagged as dangerous

    This scan re-ran every check; the current findings are detailed above.

dragon-city-1.modcombo.com is an established domain now carrying threat signals. An older domain that starts tripping security checks is a classic pattern for an asset that was sold, repurposed, or compromised — the age alone is not reassurance.

Threat Detection

Scam Network

Cross-site correlation

This site shares signals with a broader cluster

Moderate correlation

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
20/100
ClearLowModerateHighCritical
Evidence (1)
  • Cracked / modded APK download template detected.
Linked signals (3)
cdnjs.cloudflare.comt.meTemplate · Fake APK

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious59Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not queried
ESET-NOD32
Not queried
Avira
Not queried
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Not queried
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Scam-Type Likelihood

2 scam-type patterns detected
Scam-Type Likelihood

2 of 21 categories showed signals

Each card names a specific harm pattern and the concrete facts that support it. The category score is supporting context; the report verdict above remains the final severity decision.

Top match: Cracked Software — Malware Risk
Cracked Software — Malware Risk
High likelihood
83/100
  • Tagged as a cracked-software / warez site.
  • Crack / keygen / activator language.
Malware
Moderate likelihood
55/100
  • Fake-app / APK download pattern detected.
  • The evidence pattern matches malware, drive-by, or cracked-app delivery.
  • Primary scraped category: fake mobile app / APK.

Technical Details

The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbers1500-200
Postal addressNot listed
Linked social profiles5
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No postal address visible on the page.
  • Scam family match: Cracked APK / Modded App.
  • Phone number listed (1500-200).
  • Links to 7 social profiles.

Domain & Encryption

Domain History
Age6 years old
RegistrarNameSilo, LLC
RegisteredMar 10, 2020
ExpiresMar 10, 2029
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerGoogle Trust Services · WE1
ExpiresSep 11, 2026 (49d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS
Web servercloudflare

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://dragon-city-1.modcombo.com/
  • 2200https://dragon-city-1.modcombo.com/

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

What to do

Cracked-software site — malware risk

Cracks, keygens, activators, and "pre-activated" downloads are one of the most common ways people get infected.

  • Do not interact with dragon-city-1.modcombo.com

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Don't download or run any crack, keygen, or activator

    The "crack" itself is frequently an infostealer, ransomware, or miner. No antivirus can make a pirated installer safe, and disabling your AV "so the crack works" is exactly what the malware needs.

  • If you already ran one, treat the device as compromised

    Disconnect from the internet, run a full anti-malware scan, and change important passwords from a different, clean device.

  • Use official or free legitimate software instead

    Most paid tools have free tiers, trials, or open-source equivalents that carry none of this risk.

Safer Alternatives

Trying to download software? Use a safe option instead

Downloading software? Get it from the maker's official site or an official app store — "cracked", "modded", or keygen downloads are one of the most reliable ways to install malware.

The vendor's official website

Search the product name + "official" and check the domain before downloading.

Microsoft Store

Vetted Windows apps.

Ninite

Bundles legitimate free apps from their real sources.

Suggestions for safety only — not endorsements. Always verify the address bar before signing in or paying, even on well-known sites.

Final Verdict

4
Trust / 100
Final Verdict·dragon-city-1.modcombo.com
DANGEROUS

This is a modded-APK download site that distributes cracked Android games. Two independent security vendors flag the domain with low trust scores and phishing indicators.

Do not download or install any APK from this site. Stick to official app stores for Dragon City and similar games.

AV engines
92
Domain age
6 yrs
Flagged
0
Scan another URL
Security review completemalwaretips.com/url-scan

Safety FAQ

Common questions, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • dragon-city-1.modcombo.com distributes cracked / pirated software (cracks, keygens, activators), and it's high-risk. The "crack" that "activates" the software is very often the malware itself — an infostealer, ransomware, or crypto-miner — and no antivirus can make a pirated installer safe. Don't download or run anything from here; use the official version or a free, legitimate alternative.
  • No — dragon-city-1.modcombo.com scored just 4/100 on our trust scale, and we detected active threat indicators. We recommend avoiding it entirely: don't log in, pay, download anything, or connect a wallet.
  • Very possibly. Cracks, keygens, and "activators" are one of the most common malware-delivery methods — the file that "unlocks" the software is frequently an infostealer, ransomware, or crypto-miner, and these pages often tell you to disable your antivirus "so the crack works," which is exactly what the malware needs. If you already ran one, disconnect the device, run a full anti-malware scan, and change important passwords from a clean device.
  • No. Many crack and keygen pages tell you to turn off your antivirus "so the crack works" — that instruction exists because the antivirus is correctly detecting the malware inside. Even when a crack seems to work, it can quietly install an infostealer or miner in the background. If a download from dragon-city-1.modcombo.com requires you to disable protection, treat that as proof it's dangerous.
  • Downloading cracked or "pre-activated" paid software is software piracy and is illegal in most countries. On safety, it's one of the riskiest things you can do online: cracks are a top delivery method for infostealers and ransomware. Legitimate free and open-source alternatives — or a genuine free tier or trial — give you the software without the malware risk.
  • No — all 92 antivirus and blocklist engines in our malware network currently report dragon-city-1.modcombo.com as clean. That's a good sign, though antivirus coverage is only one of the many signals we weigh, and brand-new scam sites can appear clean before vendors catch up.
  • No — dragon-city-1.modcombo.com is not currently on the major browser blocklist feeds that Chrome, Safari, Firefox, and Edge rely on. Note that blocklists can lag behind brand-new scam domains, so "not listed" is reassuring but not a guarantee on its own.
  • dragon-city-1.modcombo.com is 6.4 years old, registered on March 10, 2020 through NameSilo, LLC. A multi-year registration history is one of the stronger signals against a scam, though it's never a guarantee on its own — established domains can still be misused.
  • dragon-city-1.modcombo.com resolves to an IP operated by Cloudflare, Inc. in US (Content Delivery Network). Hosting location alone doesn't make a site good or bad — but hosting that doesn't match a brand's claimed country, or that sits on networks known for abuse, is one of the many signals we weigh alongside the verdict above.
  • This report is a record of the scan run on July 23, 2026, and the verdict reflects that point in time. Scam sites change fast — they can go live, get flagged, or vanish within days — so if you believe something about dragon-city-1.modcombo.com has changed, MalwareTips staff can run a fresh scan that re-checks every signal from scratch and republishes an updated verdict.
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This automated risk assessment reflects the evidence available at scan time. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.