Highscore 54 · flagged Friday, September 11, 2026

grandpashabet-2026telegramsite.cfd

Appeared in the .cfd zone on Friday, September 11, 2026; by the end of that day the census found server error. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: telegram
+14
very long name
matched: 30
+4
brand plus digits
matched: grandpashabet-2026telegramsite
+8
TLD with a high abuse rate
matched: cfd
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+8
brand name at a watch-list registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+6
Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Nameserver provider
Nameservers
bowen.ns.cloudflare.com, jessica.ns.cloudflare.com
First-day state
server error
HTTP status
520
Page title
grandpashabet-2026telegramsite.cfd | 520: Web server is returning an unknown error
Has a form
no
Brand echoed
telegram

Model opinions

Second opinionlooks like abuseconfidence 78%· claude-opus-5

Name follows the well-known Grandpashabet mirror/affiliate pattern (brand + year + 'telegramsite') used to funnel Turkish users to an unlicensed casino via Telegram channels; the site itself returns a Cloudflare 520 with no content, so there is no impersonation, just a gambling-gateway domain on a cheap .cfd TLD via a bulk registrar.

First passsuspicioustarget: Telegramconfidence 72%· claude-haiku-4-5

The domain name contains 'telegram' and 'grandpashabet' (a known gambling brand) with suspicious structural indicators (very-long name, .cfd TLD, watched registrar), but the page is currently a Cloudflare 520 error page with no phishing content visible. The name pattern strongly suggests a gambling/betting phishing setup targeting Telegram users, but without a live phishing page to confirm credential capture or deception, the verdict cannot be elevated to phishing.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, September 11, 2026

Screenshot of grandpashabet-2026telegramsite.cfd taken by the zone census on 2026-09-11

Same data as JSON: /api/zone/domain/grandpashabet-2026telegramsite.cfd. This page is not indexed by search engines and does not link to the site it describes.