bancclogs.xyz
Appeared in the .xyz zone on Tuesday, September 1, 2026; by the end of that day the census found active website about e-commerce & retail. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Page self-brands as "Banklogs Marketplace" with a hacker-hoodie backdrop and a scrolling inventory of US bank names (Chase, Chime, Wells Fargo, Citi, BoA, Cash App, NFCU) — a criminal storefront for stolen bank account credentials, gated by an email/SMS/OAuth login for buyers rather than a page impersonating any bank to victims.
The domain bancclogs.xyz hosts a fake 'Banklogs Marketplace' login page that impersonates multiple banks including Wells Fargo, displayed prominently in the page title and content. The page collects email and phone credentials via forms posting to itself with no legitimate offsite links, matching the sealed-room phishing pattern. The branding (Wells Fargo logo/name) is used to deceive visitors into entering credentials for a criminal 'banklogs' marketplace (stolen banking data).
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 1, 2026

Same data as JSON: /api/zone/domain/bancclogs.xyz. This page is not indexed by search engines and does not link to the site it describes.