madridbet-google1.icu
Appeared in the .icu zone on Sunday, September 20, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Name combines the Turkish-facing unlicensed casino brand 'Madridbet' with 'google1', the classic SEO-gateway/mirror pattern used to funnel Turkish traffic to blocked gambling sites; the site serves a cloaked Turkish 403 page behind Cloudflare with no legitimate content, so the only plausible purpose is an unlicensed-gambling doorway rather than Google impersonation.
Domain name combines 'madridbet' (a betting brand) with 'google1' to create a typosquat/brand-squat, registered via a retail registrar with Cloudflare nameservers typical of phishing infrastructure. The 403 Forbidden page is a placeholder, not an active phishing or legitimate service; the domain's only plausible purpose is deception or takeover preparation for a gambling-related abuse campaign.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 20, 2026

Same data as JSON: /api/zone/domain/madridbet-google1.icu. This page is not indexed by search engines and does not link to the site it describes.