Highscore 46 · flagged Friday, September 25, 2026

autumncrestcapital.click

Appeared in the .click zone on Friday, September 25, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: click
+8
brand in page title, not in the name
matched: amazon
+20
form on a brand-styled page
matched: has_form
+18
Registrar
NAMECHEAP
Nameserver provider
Nameservers
clara.ns.cloudflare.com, cris.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
NAADAM The Original Cashmere Crewneck Sweater Women's (Pack of 1), Red Firecracker, L : Amazon.fr: Everything Else
Has a form
yes
Brand echoed
—

Model opinions

Second opinionsuspiciousconfidence 55%· claude-opus-5-5

The domain serves no content of its own and redirects offsite to a genuine www.amazon.fr product page (NAADAM cashmere sweater), so the Amazon branding and forms are Amazon's own and this is not phishing. However, a fresh .click name posing as a finance firm ('Autumn Crest Capital') behind Cloudflare that bounces to an unrelated retail listing fits affiliate-spam or scanner-cloaking behaviour, which is not decisive either way.

First passlooks like abuseconfidence 92%· claude-haiku-4-5

The domain 'autumncrestcapital.click' is a generic name with no brand relevance that redirects to a legitimate Amazon.fr product page. This is a typosquat/redirect abuse pattern: the domain name gives no indication it points to Amazon, making it a deceptive redirect mechanism likely used for affiliate fraud, click injection, or traffic hijacking rather than credential phishing. The .click TLD and generic name combined with offsite redirect is the signature of redirect abuse, not impersonation.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, September 25, 2026

Screenshot of autumncrestcapital.click taken by the zone census on 2026-09-25

Same data as JSON: /api/zone/domain/autumncrestcapital.click. This page is not indexed by search engines and does not link to the site it describes.