wohnungsanfrage-formular-a49b90b5f15ce514473.top
Appeared in the .top zone on Sunday, September 6, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Disposable .top name reading 'wohnungsanfrage-formular' + a random 19-hex token is the classic per-victim link used in German Kleinanzeigen rental scams, and it currently cloaks by 302'ing to the genuine www.kleinanzeigen.de behind Cloudflare NS — a warm-up/evasion posture, not a real service; the name itself impersonates a Kleinanzeigen apartment-inquiry form to harvest applicant identity/payment data.
The domain name 'wohnungsanfrage-formular-a49b90b5f15ce514473.top' (housing-inquiry-form-[random].top) is a typosquat designed to impersonate a Kleinanzeigen housing inquiry form. It redirects to the legitimate Kleinanzeigen site, creating a deceptive pathway: a victim searching for or being directed to a housing inquiry form lands on a spoofed domain that silently redirects to the real site, establishing trust before the attacker can harvest form data via the redirect chain or capture credentia
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 6, 2026

Same data as JSON: /api/zone/domain/wohnungsanfrage-formular-a49b90b5f15ce514473.top. This page is not indexed by search engines and does not link to the site it describes.