Highscore 46 · flagged Sunday, September 13, 2026

payflowex.top

Appeared in the .top zone on Sunday, September 13, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: top
+8
brand in page title, not in the name
matched: alipay
+20
form on a brand-styled page
matched: has_form
+18
Registrar
PDR Ltd.
Nameserver provider
Nameservers
ns1.hostiman.ru, ns2.hostiman.ru, ns3.hostiman.ru, ns4.hostiman.ru
First-day state
active website
HTTP status
200
Page title
Пополнить Alipay в рублях — зачисление за 5–15 минут | PayFlow
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like a scamconfidence 60%· claude-opus-5

Brand-new .top domain on Russian hosting presenting an anonymous "PayFlow" service that takes ruble card payments to top up Alipay wallets, with no legal entity, licence or company details and an operator reachable only via Telegram (5 t.me links) — the classic shape of an unlicensed/advance-fee money-transfer front; it markets Alipay top-ups rather than impersonating Alipay itself, so it is fraud risk rather than phishing.

First passlooks like a scamconfidence 92%· claude-haiku-4-5

PayFlow is a third-party money transfer service offering to convert rubles to Alipay yuan, not impersonating Alipay itself. The page clearly identifies as 'PayFlow' with its own branding and logo. However, this is a scam because it collects personal data (name, phone, email, amount) via a form posting to itself with no legitimate payment processing infrastructure, directs users to contact via Telegram only, and exhibits the sealed-room phishing pattern—the operator waiting on Telegram is the tel

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 13, 2026

Screenshot of payflowex.top taken by the zone census on 2026-09-13

Same data as JSON: /api/zone/domain/payflowex.top. This page is not indexed by search engines and does not link to the site it describes.