Is it gathering data from your cookies for dodgy purposes? Could be a scam?
I'm pretty sure cookies are tied to the TLD or something. You can steal a cookie using cross-site scripting, but that would be a security breach on the website the cookie belongs to, not you visiting a malicious site. I suppose if a browser exploit gave them system access they could do whatever they liked.