xn--bitefill-nub.com
Appeared in the .com zone on Tuesday, September 22, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name decodes to 'bitŗefill', a Cyrillic/Latin homoglyph spoof of the crypto gift-card service Bitrefill — a deliberate IDN typosquat whose only plausible purpose is deception; it currently serves no content of its own, just a throwaway redirect to google.com behind Cloudflare NS, so the Google branding in the evidence belongs to the destination and is not impersonation by this domain.
The domain xn--bitefill-nub.com (punycode for bitŗefill.com) is a typosquat using a homoglyph attack (ŗ instead of e) combined with an off-site redirect to www.google.com. The domain name itself has no legitimate business purpose; it appears designed to deceive users into visiting a lookalike domain before redirecting them. This is a brand-squat abuse tactic, not phishing (since the actual destination is Google's real site, not an impersonation), but the deceptive registration and redirect mecha
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 22, 2026

Same data as JSON: /api/zone/domain/xn--bitefill-nub.com. This page is not indexed by search engines and does not link to the site it describes.