gopay777-mobile.site
Appeared in the .site zone on Monday, September 14, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Default Chinese-panel 'Site is created successfully!' placeholder with no content, one of a 117-page identical cluster behind Cloudflare NS — a bulk-registered domain awaiting content. The name follows the Indonesian slot-gambling naming convention (payment brand 'GoPay' + lucky '777' + 'mobile'), suggesting an unlicensed gambling or payment-brand-squat front, but the page itself shows nothing deceptive yet; the scorer's 'tmobile' leet match is a false positive.
The domain gopay777-mobile.site contains a brand-leet obfuscation of T-Mobile and uses digits (777) common in phishing campaigns. However, the page itself is a generic hosting placeholder with no phishing content—no login form, no impersonation, no deceptive material. The evidence of 117 identical pages across a cluster suggests this is a bulk typosquat registration campaign awaiting deployment rather than active phishing. The verdict is abuse (brand-squat infrastructure) rather than phishing (n
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Monday, September 14, 2026

Same data as JSON: /api/zone/domain/gopay777-mobile.site. This page is not indexed by search engines and does not link to the site it describes.