Highscore 56 · flagged Monday, August 31, 2026

xn----7sbbaad5fbdbf.online

Appeared in the .online zone on Monday, August 31, 2026; by the end of that day the census found active website about ai software. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

punycode name
matched: нано-банана scripts=CYRILLIC
+18
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Registrar of Domain Names REG.RU LLC
Nameserver provider
Nameservers
ns1.reg.ru, ns2.reg.ru
First-day state
active website
HTTP status
200
Page title
Нано банана: здесь рисует Seedream 4.0 — Кадр
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks benignconfidence 72%· claude-opus-5

Punycode domain нано-банана.online hosts a self-branded Russian AI image-generation landing page ("Кадр") whose own text explicitly states that "nano banana" is a nickname for Google's model but that images here are produced by ByteDance Seedream 4.0 — a disclaimer, not impersonation; the only form is a prompt textarea, with no credential or payment capture, and offsite links go to an affiliate tracker (ai.trackly.one), making this an affiliate/SEO funnel rather than phishing.

First passlooks like phishingtarget: Googleconfidence 92%· claude-haiku-4-5

The page impersonates Google's Gemini image generation service by falsely claiming 'Нано банана — это Gemini 2.5 Flash Image от Google' (Nano banana is Google's Gemini 2.5 Flash), but actually delivers ByteDance's Seedream 4.0. A form collecting user input ('Опишите кадр') posts to itself with no verification of legitimacy, using a Cyrillic punycode domain to obscure the deception—a classic sealed-room phishing pattern designed to harvest descriptions and potentially credential data under false

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Monday, August 31, 2026

Screenshot of xn----7sbbaad5fbdbf.online taken by the zone census on 2026-08-31

Same data as JSON: /api/zone/domain/xn----7sbbaad5fbdbf.online. This page is not indexed by search engines and does not link to the site it describes.