Highscore 46 · flagged Friday, September 11, 2026

revolutionvisuals.fun

Appeared in the .fun zone on Friday, September 11, 2026; by the end of that day the census found empty page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: revolut
+30
TLD with a high abuse rate
matched: fun
+8
brand name at a retail registrar
matched: PDR Ltd. d/b/a PublicDomainRegistry.com
+8
Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Nameserver provider
Nameservers
ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, ns4.timeweb.org
First-day state
empty page
HTTP status
200
Page title
Revolution Visuals
Has a form
no
Brand echoed
revolut

Model opinions

Second opinionsuspiciousconfidence 52%· claude-opus-5

No impersonation: the 'revolut' brand hit is a coincidental substring of 'Revolution Visuals', a Russian-language site selling what appears to be a Minecraft game cheat/client ('raise your gameplay to a new level — control, speed, precision') with Docs/Purchase/Support pages and Telegram as operator contact. Its own brand and login, so not phishing, but paid game-cheat distribution via Telegram on a .fun domain is a known vector for bundled malware and warrants monitoring rather than a clean ver

First passlooks like phishingtarget: Revolutconfidence 92%· claude-haiku-4-5

The domain uses 'revolut' (Revolut's brand name) combined with a suspicious .fun TLD and Russian nameservers. The page is in Russian, presents itself as 'Revolution Visuals' with Revolut-like branding, includes login buttons ('Войти' = Sign in, 'Создать аккаунт' = Create account), and lists Telegram as operator contact—a classic phishing setup designed to harvest credentials by impersonating the Revolut fintech platform.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, September 11, 2026

Screenshot of revolutionvisuals.fun taken by the zone census on 2026-09-11

Same data as JSON: /api/zone/domain/revolutionvisuals.fun. This page is not indexed by search engines and does not link to the site it describes.