Highscore 48 · flagged Sunday, September 20, 2026

northglass-archive-47-morrow-field-82-lantern.party

Appeared in the .party zone on Sunday, September 20, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

many hyphens
matched: 6
+6
very long name
matched: 45
+4
brand in page title, not in the name
matched: cloudflare
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
ian.ns.cloudflare.com, tia.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Sign in ・ Cloudflare Access
Has a form
yes
Brand echoed

Model opinions

Second opinionsuspiciousconfidence 55%· claude-opus-5

The domain is a random word-and-number salad on .party (northglass-archive-47-morrow-field-82-lantern) that serves no content of its own but is gated behind a genuine Cloudflare Access login (super-art-4464.cloudflareaccess.com, 'Log in to Candy After Dark') — the Cloudflare branding is the real Zero Trust portal, not impersonation. Algorithmic naming plus an access-gated hidden app is a pattern often used to conceal infrastructure, but nothing visible proves abuse.

First passlooks like phishingtarget: Cloudflareconfidence 95%· claude-haiku-4-5

The domain redirects to a counterfeit Cloudflare Access login page (super-art-4464.cloudflareaccess.com) that impersonates Cloudflare's branding, logo, and UI to collect email credentials. The page falsely claims to be a login for 'Candy After Dark' while displaying Cloudflare Access branding and requesting email submission via a form posting to the attacker's infrastructure, a classic phishing technique.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 20, 2026

Screenshot of northglass-archive-47-morrow-field-82-lantern.party taken by the zone census on 2026-09-20

Same data as JSON: /api/zone/domain/northglass-archive-47-morrow-field-82-lantern.party. This page is not indexed by search engines and does not link to the site it describes.