fl2tbjbihljo9g8.icu
Appeared in the .icu zone on Tuesday, September 15, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Random-string hostname on a cheap .icu TLD behind Cloudflare NS serves no content of its own and 302s to the genuine www.apple.com; the Apple branding in the title/screenshot is the destination's, not this domain's. A throwaway gibberish name whose only function is an offsite redirect to a major brand's real site is the classic cloaking/decoy leg of an SMS or email lure (legitimate traffic gets apple.com, targeted visitors get the phish), but with no malicious payload observed the evidence is no
The domain fl2tbjbihljo9g8.icu is a nonsensical string with no legitimate purpose, registered via NameSilo and hosted on Cloudflare nameservers, that redirects to www.apple.com. This is a classic brand-squat setup: the obfuscated domain name and redirect infrastructure indicate intent to deceive visitors into thinking they are accessing Apple's site from a spoofed URL, likely for credential capture or traffic manipulation via the redirect chain.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 15, 2026

Same data as JSON: /api/zone/domain/fl2tbjbihljo9g8.icu. This page is not indexed by search engines and does not link to the site it describes.