Highscore 55 · flagged Saturday, September 5, 2026

bank0fameric-a-link.net

Appeared in the .net zone on Saturday, September 5, 2026; by the end of that day the census found placeholder page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand spelled with digits
matched: bank0fameric-a-link→bankofamerica
+35
brand plus digits
matched: bank0fameric-a-link
+8
brand name on a rarely-seen nameserver
matched: koddos.com
+6
brand name at a retail registrar
matched: PDR Ltd. d/b/a PublicDomainRegistry.com
+8
Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Nameserver provider
Nameservers
hk3.koddos.com, hk4.koddos.com
First-day state
placeholder page
HTTP status
200
Page title
Index of /
Has a form
no
Brand echoed
bankofamerica

Model opinions

Second opinionlooks like abusetarget: Bank of Americaconfidence 76%· claude-opus-5

bank0fameric-a-link.net is a leetspeak (0-for-o) impersonation of bankofamerica hosted on KoDDoS bulletproof-style nameservers via a retail registrar; the site currently serves only an open LiteSpeed directory index exposing 'demobank_private', 'public_html' and a CPANEL-SETUP.md, i.e. a bank kit being staged with no deceptive page live yet — a brand-squat whose only plausible purpose is a future Bank of America credential phish.

First passlooks like abusetarget: Bank of Americaconfidence 92%· claude-haiku-4-5

Domain is a leet-speak typosquat of Bank of America (bank0fameric-a-link → bankofamerica) registered with bulletproof hosting (Koddos nameservers) and showing a generic placeholder/directory listing with no legitimate content. The infrastructure and name composition indicate brand-squatting infrastructure ready for phishing deployment, though the current page state is merely a directory listing rather than an active phishing form.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, September 5, 2026

Screenshot of bank0fameric-a-link.net taken by the zone census on 2026-09-05

Same data as JSON: /api/zone/domain/bank0fameric-a-link.net. This page is not indexed by search engines and does not link to the site it describes.