Highscore 55 · flagged Friday, August 28, 2026

jinhulu2fanpaijishoujibandanjiban.casa

Appeared in the .casa zone on Friday, August 28, 2026; by the end of that day the census found parked, for sale. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: hulu
+14
very long name
matched: 33
+4
brand plus digits
matched: jinhulu2fanpaijishoujibandanjiban
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Dynadot Inc
+8
brand name at a watch-list registrar
matched: Dynadot Inc
+6
identical page on many newborns
matched: 11037 identical pages
+10
Registrar
Dynadot Inc
Nameserver provider
Nameservers
molly.ns.cloudflare.com, roman.ns.cloudflare.com
First-day state
parked, for sale
HTTP status
403
Page title
403 Forbidden
Has a form
no
Brand echoed
hulu

Model opinions

Second opinionsuspiciousconfidence 50%· claude-opus-5

The "hulu" match is a false positive inside a long Chinese pinyin string (likely "jin hulu ... fan pai ji shou ji ban"), so there is no brand impersonation; the site serves only an nginx 403 with no content or forms. The only real signal is membership in an 11k-page identical cluster typical of bulk Chinese SEO/gambling registrations, which is not decisive on its own.

First passlooks like abuseconfidence 88%· claude-haiku-4-5

The domain is a brand-typosquat on 'Hulu' with an obfuscated name (jinhulu2fanpaijishoujibandanjiban) and returns a 403 Forbidden nginx placeholder page. The census marks it as parked-for-sale, and the scorer evidence shows it clusters with 11,037 identical placeholder pages—a classic bulk typosquat campaign. No actual phishing page content is present, only a parking/infrastructure placeholder, so this is squat abuse rather than active phishing.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, August 28, 2026

Screenshot of jinhulu2fanpaijishoujibandanjiban.casa taken by the zone census on 2026-08-28

Same data as JSON: /api/zone/domain/jinhulu2fanpaijishoujibandanjiban.casa. This page is not indexed by search engines and does not link to the site it describes.