Highscore 55 · flagged Friday, October 2, 2026

outlookverbatin130emjf39lfokfkk9kfkkf47.sbs

Appeared in the .sbs zone on Friday, October 2, 2026; by the end of that day the census found empty page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: outlook
+30
very long name
matched: 39
+4
brand plus digits
matched: outlookverbatin130emjf39lfokfkk9kfkkf47
+8
TLD with a high abuse rate
matched: sbs
+8
brand name at a retail registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+8
brand name at a watch-list registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+6
Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Nameserver provider
Nameservers
ns3.my-ndns.com, ns4.my-ndns.com
First-day state
empty page
HTTP status
200
Page title
—
Has a form
no
Brand echoed
outlook

Model opinions

Second opinionlooks like phishingtarget: Microsoft (Outlook)confidence 86%· claude-opus-5-5

A throwaway 'outlook'+random-string .sbs name (NiceNIC) serves a fake 'Checking your browser' slider gate, not a real Cloudflare challenge, in Microsoft-blue styling. Its hidden-field form (next/nonce/sig/path) posts to a separate .cfd host, the anti-bot gate shape that phishing kits put in front of an Outlook credential-harvest page.

First passlooks like phishingtarget: Microsoft Outlookconfidence 95%· claude-haiku-4-5

Domain impersonates Outlook with 'outlook' in a typosquat name; the page shows a fake 'Checking your browser' challenge with human verification language and a slider, a known phishing pattern used to harvest credentials. The form posts to endpointssession.cfd (an external attacker domain), confirming credential capture infrastructure.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, October 2, 2026

Screenshot of outlookverbatin130emjf39lfokfkk9kfkkf47.sbs taken by the zone census on 2026-10-02

Same data as JSON: /api/zone/domain/outlookverbatin130emjf39lfokfkk9kfkkf47.sbs. This page is not indexed by search engines and does not link to the site it describes.