Criticalscore 60 · flagged Friday, August 28, 2026

teosbet-mobilerisimim.top

Appeared in the .top zone on Friday, August 28, 2026; by the end of that day the census found active website about hosting & domains. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: tmobile
+14
TLD with a high abuse rate
matched: top
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Dynadot LLC
+8
brand name at a watch-list registrar
matched: Dynadot LLC
+6
form on a brand-styled page
matched: has_form
+18
Registrar
Dynadot LLC
Nameserver provider
Nameservers
haley.ns.cloudflare.com, sonny.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
ICQ Oto Systems
Has a form
yes
Brand echoed
tmobile

Model opinions

Second opinionlooks like abuseconfidence 62%· claude-opus-5

Name is a Turkish gambling mirror pattern ("teosbet" + "mobil erişim" = mobile access to the unlicensed Teosbet betting brand), and the site serves an operator-only "ICQ Oto Systems" admin panel for bulk domain/Cloudflare/WHM/cPanel management and URL monitoring — i.e. tooling for running gambling-mirror/blackhat-SEO domain networks, not a service for visitors. The scorer's "tmobile" hit is a false positive from "teosbet-mobile", and the ICQ logo reuse is branding of the panel, not credential ph

First passlooks like phishingtarget: ICQconfidence 95%· claude-haiku-4-5

The page impersonates ICQ's branding (logo, product name 'ICQ Oto Systems') to present a fake admin login portal. The form posts to itself with no offsite links, the domain name includes a garbled Turkish phrase suggesting obfuscation, and the sealed-room phishing architecture (self-posting credentials form with no legitimate redirect) confirms credential harvesting intent.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, August 28, 2026

Screenshot of teosbet-mobilerisimim.top taken by the zone census on 2026-08-28

Same data as JSON: /api/zone/domain/teosbet-mobilerisimim.top. This page is not indexed by search engines and does not link to the site it describes.