n96ci7au.top
Appeared in the .top zone on Monday, August 31, 2026; by the end of that day the census found active website about hosting & domains. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Random alphanumeric .top name serving only a Chinese-language anti-CC 'access via the domain name' CDN interstitial (node '91大带宽USA', Xcdn) — infrastructure typical of Chinese gambling/scam fronts hidden behind bulletproof CDNs, but no actual content or brand impersonation is visible; the scorer's 'itau' leet match on n96ci7au is not credible.
The domain name n96ci7au.top uses leet-speak encoding ('96ci7au' → 'itau'), a common typosquat technique for the Brazilian bank Itaú. However, the current page is a generic CDN access-control message with no phishing form, credential capture attempt, or brand impersonation visible. The page appears to be a hosting placeholder or misconfiguration rather than an active phishing campaign, but the encoded brand-name in the domain combined with obfuscated nameservers (Jindun DNS) and the .top TLD sug
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Monday, August 31, 2026

Same data as JSON: /api/zone/domain/n96ci7au.top. This page is not indexed by search engines and does not link to the site it describes.