Highscore 54 · flagged Saturday, August 29, 2026

loginbinance-tr.online

Appeared in the .online zone on Saturday, August 29, 2026; by the end of that day the census found empty page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: binance
+14
lure words (login, verify, secure…)
matched: login
+26
brand name at a retail registrar
matched: Dynadot Inc
+8
brand name at a watch-list registrar
matched: Dynadot Inc
+6
Registrar
Dynadot Inc
Nameserver provider
Nameservers
ns1.dyna-ns.net, ns2.dyna-ns.net
First-day state
empty page
HTTP status
200
Page title
Has a form
no
Brand echoed
binance

Model opinions

First passsuspicioustarget: Binanceconfidence 72%· claude-haiku-4-5

Domain name combines 'login' and 'binance' with a country code suffix (-tr for Turkey), a classic phishing pattern. However, the page currently returns only a 403 Forbidden error with no content, so there is no active impersonation page to confirm the phishing attempt. The infrastructure (Dynadot registrar, dyna-ns nameservers) and name construction are consistent with phishing setup, but the lack of an actual login form or brand impersonation on the page prevents a definitive phishing verdict a

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, August 29, 2026

Screenshot of loginbinance-tr.online taken by the zone census on 2026-08-29

Same data as JSON: /api/zone/domain/loginbinance-tr.online. This page is not indexed by search engines and does not link to the site it describes.