Highscore 50 · flagged Thursday, September 10, 2026

chase-accessportal.info

Appeared in the .info zone on Thursday, September 10, 2026; by the end of that day the census found empty page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

ambiguous brand word
matched: chase
+4
lure words (login, verify, secure…)
matched: access,portal
+32
brand name at a retail registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+8
brand name at a watch-list registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+6
Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Nameserver provider
Nameservers
ns3.my-ndns.com, ns4.my-ndns.com
First-day state
empty page
HTTP status
200
Page title
Has a form
no
Brand echoed
chase

Model opinions

Second opinionlooks like abusetarget: Chase Bankconfidence 78%· claude-opus-5

Domain concatenates the Chase bank brand with banking-login lure words ('access portal') and serves a blank 200 page with no content or links, registered through a bulk offshore registrar (NiceNIC) on non-brand nameservers — a staged brand-squat whose only plausible purpose is a future Chase credential page; no deceptive content is live yet, so not scored as active phishing.

First passlooks like phishingtarget: Chase Bankconfidence 95%· claude-haiku-4-5

Domain name 'chase-accessportal.info' directly impersonates Chase Bank's brand combined with 'access portal' lure language. The page returns HTTP 200 but displays blank content (likely a credential-harvesting form in development or obfuscated), is registered through a high-risk registrar (NICENIC), uses suspicious nameservers, and matches the sealed-room phishing pattern: no outbound links, no legitimate brand content, only inbound credential capture intended.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, September 10, 2026

Screenshot of chase-accessportal.info taken by the zone census on 2026-09-10

Same data as JSON: /api/zone/domain/chase-accessportal.info. This page is not indexed by search engines and does not link to the site it describes.