Highscore 46 · flagged Tuesday, September 1, 2026

dqlpfcrtgv.click

Appeared in the .click zone on Tuesday, September 1, 2026; by the end of that day the census found active website about finance loans. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: click
+8
brand in page title, not in the name
matched: ledger
+20
form on a brand-styled page
matched: has_form
+18
Registrar
NameSilo, LLC
Nameserver provider
Nameservers
opal.ns.cloudflare.com, sterling.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
LUMEN Ledger | Finance Operations Cloud
Has a form
yes
Brand echoed

Model opinions

Second opinionsuspiciousconfidence 62%· claude-opus-5

Polished Japanese "LUMEN Ledger / Finance Operations Cloud" corporate SaaS page — its own invented brand, not the Ledger hardware-wallet brand — sitting on a random ten-character .click domain registered hours ago behind Cloudflare, with only a contact form (name/email placeholders 山田太郎) and no genuine company identifiers or offsite links; the mismatch between a random throwaway name and a generated fintech front is a real signal but there is no credential capture or impersonation yet to call it

First passlooks like phishingtarget: LUMEN Ledgerconfidence 92%· claude-haiku-4-5

The domain dqlpfcrtgv.click hosts a complete LUMEN Ledger Finance Operations Cloud interface with a password form (山田 太郎 / name@company.co.jp) that posts to itself with no offsite links—a sealed-room phishing pattern. The page title and all content impersonate LUMEN Ledger's branding and dashboard UI, but the random domain name and self-posting form indicate credential harvesting, not the legitimate service.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 1, 2026

Screenshot of dqlpfcrtgv.click taken by the zone census on 2026-09-01

Same data as JSON: /api/zone/domain/dqlpfcrtgv.click. This page is not indexed by search engines and does not link to the site it describes.