Criticalscore 68 · flagged Sunday, October 4, 2026

babalivakito.bond

Appeared in the .bond zone on Sunday, October 4, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: bond
+8
page impersonates a brand
matched: Amazon Prime
+22
brand in page title, not in the name
matched: amazon
+20
form on a brand-styled page
matched: has_form
+18
Registrar
HOSTINGER operations, UAB
Nameserver provider
Nameservers
atlas.dns-parking.com, hyperion.dns-parking.com
First-day state
active website
HTTP status
200
Page title
NEXUS PRIME | Curated 2026 Amazon Best Tech & Smart Living Deals
Has a form
yes
Brand echoed
—

Model opinions

Second opinionlooks benignconfidence 68%· claude-opus-5-5

This is an Amazon affiliate deals page: 22 links go to the real amazon.com with the associate tag 'tonnuhoanglan-20', and the only form is a GET search posting to itself, with no password or payment capture. The 'Authentic Amazon Partner' and 'Official Prime' claims and the fake countdown are marketing overreach, not credential phishing, and the nonsense domain name is not a brand-squat.

First passlooks like phishingtarget: Amazon Primeconfidence 92%· claude-haiku-4-5

The page impersonates Amazon Prime with brand language ('PRIME EXCLUSIVE', 'Authentic Amazon Partner', '2026 OFFICIAL PRIME CURATION'), Amazon-styled UI elements, and claims of official curation, but is hosted on an unrelated domain (babalivakito.bond) with parking nameservers. The presence of a search form posting to itself combined with 22 outbound links to www.amazon.com follows the sealed-room phishing pattern: decoy links to the real site to appear legitimate while the form captures input l

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, October 4, 2026

Screenshot of babalivakito.bond taken by the zone census on 2026-10-04

Same data as JSON: /api/zone/domain/babalivakito.bond. This page is not indexed by search engines and does not link to the site it describes.