Mediumscore 38 · flagged Sunday, September 20, 2026

chumos.cloud

Appeared in the .cloud zone on Sunday, September 20, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in page title, not in the name
matched: cloudflare
+20
form on a brand-styled page
matched: has_form
+18
Registrar
HOSTINGER operations, UAB
Nameserver provider
Nameservers
dax.ns.cloudflare.com, kristin.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Sign in ・ Cloudflare Access
Has a form
yes
Brand echoed

Model opinions

First passsuspiciousconfidence 72%· claude-haiku-4-5

The domain chumos.cloud redirects to a Cloudflare Access login page that claims to protect a 'ChumOS Dashboard' and offers Cloudflare OAuth as a sign-in method. This is a legitimate Cloudflare Access configuration (not impersonation of Cloudflare itself), but the setup—a newly registered domain with an obscure name redirecting to a generic access portal—is consistent with either a real service requiring access control or a phishing infrastructure. The presence of email+login-code collection on a

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/chumos.cloud. This page is not indexed by search engines and does not link to the site it describes.