Criticalscore 60 · flagged Wednesday, September 2, 2026

insesa-costarica.com

Appeared in the .com zone on Wednesday, September 2, 2026; by the end of that day the census found active website about gaming. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: insesa≈intesa
+28
brand name at a retail registrar
matched: GMO Internet Group, Inc. d/b/a Onamae.co
+8
form on a brand-styled page
matched: has_form
+18
form submits over plain HTTP
matched: http://insesa-costarica.com/
+6
Registrar
GMO Internet Group, Inc. d/b/a Onamae.com
Nameserver provider
Nameservers
a1.share-dns.com, b1.share-dns.net
First-day state
active website
HTTP status
200
Page title
爱游戏官方网页版-爱游戏(中国)
Has a form
yes
Brand echoed
intesa

Model opinions

Second opinionlooks like abuseconfidence 78%· claude-opus-5

Page serves a cloned Chinese slaughtering-machinery site whose title and body text are keyword-stuffed with 爱游戏 (AiYouXi, an unlicensed Chinese gambling brand), plus 181 links into a farm of unrelated Chinese hosts and a form posting to cmspost.hnjing.cn — the classic black-hat SEO / gambling-promotion doorway shape, not Intesa phishing (the 'insesa≈intesa' typo hit is coincidental).

First passlooks like abuseconfidence 85%· claude-haiku-4-5

The domain insesa-costarica.com is a typosquat of Intesa (a banking/financial brand), registered with a Chinese nameserver (share-dns.com/net) and hosting a Chinese-language page about slaughterhouse equipment (爱游戏) that has nothing to do with Costa Rica or the typosquatted brand. The form posts to a Chinese server (cmspost.hnjing.cn) collecting names, phones, and emails—a classic credential/data harvesting pattern. This is brand-squatting infrastructure repurposed for fraud, not a legitimate bu

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Wednesday, September 2, 2026

Screenshot of insesa-costarica.com taken by the zone census on 2026-09-02

Same data as JSON: /api/zone/domain/insesa-costarica.com. This page is not indexed by search engines and does not link to the site it describes.