bianbinancexiazai.casa
Appeared in the .casa zone on Friday, August 28, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Domain is Chinese pinyin for "Binance download" (bian[bi'an] + binance + xiazai), an unambiguous brand-squat of Binance with no content yet (nginx 403), and it sits in a cluster of 11,037 identical placeholder pages behind Cloudflare NS — a staged campaign whose only plausible purpose is to serve fake Binance app/download lures.
Domain name contains 'binance' typosquat (bianbinancexiazai.casa); currently shows 403 Forbidden nginx placeholder, but the scorer reports 11,037 identical pages in a cluster—a classic mass-deployment phishing campaign signature. The combination of brand-in-name, Cloudflare nameservers, retail registrar, and massive page-cluster count indicates prepared infrastructure for phishing, even though the current page is a boilerplate error state.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Friday, August 28, 2026

Same data as JSON: /api/zone/domain/bianbinancexiazai.casa. This page is not indexed by search engines and does not link to the site it describes.