Verdict
198macros.org shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | A site offering a cracked version of the '198 Macros' Minecraft mod (JAR) for Fabric 26.2 and 1.21, with feature descriptions and install instructions. No payment is requested; the content openly admits to being an unofficial crack and warns it is not affiliated with the original. No publisher verification or safety/audit information for the binary is provided. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 2 months oldMost scam domains are under a year old | Risk |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by WE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- No flags from the reputation services TrustSniffer consulted at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Security Alert
Fortinet flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
This website presents itself as a free-download distribution site for a cracked version of the “198 Macros” Minecraft modification, offering Fabric 26.2 and 1.21 builds, feature descriptions, and installation instructions for a JAR file intended to automate competitive player-versus-player gameplay.
Scam/Impersonation Risk
No confirmed blacklist, phishing, impersonation, or conflicting legal-identity contradiction was observed. However, the homepage openly describes the software as an unofficial crack of a premium product and instructs visitors to place a JAR in the Minecraft mods folder or double-click it for auto-injection. It advertises Crystal, Anchor, Mace, and Sword combat automation, configurable delays and key bindings, and a “latest crack,” but provides no publisher verification, binary safety assessment, or audit information. This downloadable executable and the openly pirated distribution model create a material software-safety and legal-status concern. Separately, an external security-intelligence signal identified the site as suspicious through Fortinet; this is a soft reputational warning rather than a confirmed blacklist finding. Evidence:
- The homepage labels the offering “Cracked” and states that it is not affiliated with the original product.
- The homepage provides JAR installation and auto-injection instructions for Fabric 26.2 and 1.21.
- The homepage describes Crystal, Anchor, Mace, and Sword automation with configurable delays, slots, and key bindings.
- External assessment recorded one suspicious detection and no confirmed malicious result or blacklist hit.
Regulatory Verification Notes
The site’s apparent business model is distribution of pirated software rather than a regulated financial or commercial service, so conventional licensing evidence is not applicable in the same way as it would be for a broker or payment provider. Nevertheless, the available homepage material does not establish a verifiable publisher, corporate operator, authorization to distribute the software, or safety assurance for the binary. The operator’s real-world identity remains unverified, and the content provides an unclear basis for accountability. The domain is very recently registered, which is relevant context for a site distributing an executable file. Evidence:
- Domain registration records show creation on 2026-08-07 and an age of 0.13 years; registrar: Web Commerce Communications Limited dba WebNic.cc.
- The homepage presents the software as an unofficial crack and does not identify a verifiable publisher or distribution authorization.
- The site’s transport security uses a DV certificate issued by WE1, valid to 2026-11-07.
- The site is served on AS13335 by CLOUDFLARENET – Cloudflare, Inc., US.
What to Verify Next
Before any download or execution, an enterprise or prospective user should independently confirm the publisher’s identity and authorization through the original software developer’s official channels, obtain the software from an authorized distribution source, and submit any downloaded binary to controlled malware analysis rather than executing it on a production or personal system. Any claimed community or support channel should be confirmed through an independently established source, and the file’s cryptographic provenance should be checked against publisher-issued values if such values exist. Evidence:
- The homepage provides no publisher verification or binary safety/audit information.
- The site’s stated distribution model is an unofficial crack rather than an authorized release.
- The analyzed page contains no login or sensitive form, but it does provide a downloadable executable file.
Summary Verdict
The website has a critical trust posture for interaction involving downloads or execution. Its apparent purpose is clear, but the combination of unverified operator identity, very recent registration, pirated software distribution, executable delivery, and an external suspicious detection does not support treating it as a dependable software source.
Infrastructure Integrity
Cloudflare CDN and WAF protection provide a genuine layer of delivery and exposure mitigation, but they do not establish the legitimacy of the operator or the safety of the hosted file. The observed infrastructure consisted of Cloudflare edge addresses, with no origin server address identified in the supplied analysis.
Closing Assessment
The proportionate enterprise response is to prohibit download and execution from this site unless independent publisher confirmation, file provenance, and isolated security testing have first been completed.
Written analysis generated 2026-09-24 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
1 finding contributed to this verdict, raised by registration and ownership.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of 198macros.org.
- The request stayed on 198macros.org. It was not redirected to another domain. Clear
- Registration is published under Web Commerce Communications Limited dba WebNic.cc. Clear
- DNS for this domain is served by cloudflare.com, across 2 name servers. Noted
- The registration is paid up to 2027-08-07. Noted
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Web Commerce Communications Limited dba WebNic.cc |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:3035::6815:5bf4 |
| Name servers | andy.ns.cloudflare.com, brenna.ns.cloudflare.com |
| SSL issuer | WE1 |
| SSL expiry | 2026-11-07 |
| Domain age | 0.13 years (continuous registration) |
| Domain expiry | 2027-08-07 |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about 198macros.org at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.