holiganbet-gunceliii.icu
Appeared in the .icu zone on Sunday, September 6, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name is a Turkish 'güncel giriş' (current login mirror) domain for the Holiganbet gambling brand — a well-known pattern of throwaway .icu/.xyz mirror domains used to evade Turkish gambling blocks — and it currently cloaks by redirecting to dns.google rather than serving content, so the Google Public DNS branding is not this domain's. Judged as an unlicensed-gambling mirror/brand-squat front, not phishing.
The domain holiganbet-gunceliii.icu is a typosquat/brand-squat with no legitimate purpose: it redirects to Google's legitimate dns.google service, masking its true identity behind a gambling-related name (holiganbet suggests a betting operation). The .icu TLD, Cloudflare nameservers, and NICENIC registrar combination is typical of abuse infrastructure. The redirect itself is the deception mechanism — visitors typing or being directed to this domain believe they are accessing a betting site, not
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 6, 2026

Same data as JSON: /api/zone/domain/holiganbet-gunceliii.icu. This page is not indexed by search engines and does not link to the site it describes.