Criticalscore 82 · flagged Wednesday, September 2, 2026

maps-lcloud.site

Appeared in the .site zone on Wednesday, September 2, 2026; by the end of that day the census found active website about hosting & domains. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: lcloud≈icloud
+28
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: EuroDNS S.A.
+8
page impersonates a brand
matched: PayPal
+22
form on a brand-styled page
matched: has_form
+18
Registrar
EuroDNS S.A.
Nameserver provider
Nameservers
aragorn.ns.cloudflare.com, carrera.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
Thor-Server
Has a form
yes
Brand echoed
icloud

Model opinions

Second opinionlooks like abusetarget: Apple iCloudconfidence 72%· claude-opus-5

The name typosquats Apple's iCloud/Find-My branding (maps-lcloud ≈ maps/icloud) while the site is an IMEI/'unlocker' platform selling activation-lock and carrier unlocks with credit top-ups, Telegram-only operator contact, and fabricated trust stats — a grey-market/stolen-device unlocking front, not a legitimate business; the PayPal string is only a checkout option, not brand impersonation.

First passlooks like abuseconfidence 92%· claude-haiku-4-5

The domain maps-lcloud.site hosts ThorServer, a legitimate unlicensed IMEI-unlocking service with its own branding and login system. While the domain name contains 'lcloud' (a typosquat of iCloud) and the scorer flagged PayPal impersonation, the page itself presents ThorServer as its own platform—not impersonating PayPal, Apple, or another brand to steal credentials. This is abuse (brand-squat + unlicensed service) rather than phishing, as the deception is in the domain name and the service itse

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Wednesday, September 2, 2026

Screenshot of maps-lcloud.site taken by the zone census on 2026-09-02

Same data as JSON: /api/zone/domain/maps-lcloud.site. This page is not indexed by search engines and does not link to the site it describes.