Criticalscore 82 · flagged Saturday, August 29, 2026

lcloud-alert.xyz

Appeared in the .xyz zone on Saturday, August 29, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: lcloud≈icloud
+28
lure words (login, verify, secure…)
matched: alert
+26
TLD with a high abuse rate
matched: xyz
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Dynadot Inc
+8
brand name at a watch-list registrar
matched: Dynadot Inc
+6
Registrar
Dynadot Inc
Nameserver provider
Nameservers
art.ns.cloudflare.com, martha.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
A2osX
Has a form
no
Brand echoed
icloud

Model opinions

Second opinionlooks like abusetarget: Apple (iCloud)confidence 66%· claude-opus-5

The name is a homoglyph typosquat of iCloud combined with the classic SMS/email lure word 'alert' (lcloud-alert), while the site serves only an unrelated stock HTML5 UP template about a hobbyist Apple II OS project — placeholder content parked under a brand-squat name whose only plausible purpose is a later iCloud credential lure; no deceptive form is live yet, so it is not scored as phishing.

First passsuspiciousconfidence 72%· claude-haiku-4-5

The domain name 'lcloud-alert.xyz' strongly resembles 'icloud' (Apple's service) combined with the lure word 'alert', and scorer flags brand+cloudflare-ns correlation. However, the page content is a legitimate A2osX operating-system project site with no login form, credential capture attempt, or impersonation of Apple, iCloud, or any other brand. The mismatch between the suspicious domain name and benign page content suggests either domain abuse (squat) or misconfiguration, but not active phishi

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, August 29, 2026

Screenshot of lcloud-alert.xyz taken by the zone census on 2026-08-29

Same data as JSON: /api/zone/domain/lcloud-alert.xyz. This page is not indexed by search engines and does not link to the site it describes.