xn--drry38h.lol
Appeared in the .lol zone on Thursday, September 10, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Short punycode CJK throwaway name (启航.lol) on a cheap TLD that serves no content of its own but bounces all 48 links to sg001.cc, a Chinese pay-per-view adult site pushing a 'login token' and 'permanent address, screenshot to save' modal — the classic disposable mirror-domain shape used to keep an illicit adult/piracy portal reachable. The 'My Google AI Studio App' title is leftover AI-generated boilerplate on the destination, not Google impersonation.
The punycode domain (启航, 'set sail') with .lol TLD redirects to sg001.cc, which presents a page titled 'My Google AI Studio App' with a modal dialog in Chinese offering two red-button actions: 'Copy Link' and 'Copy Login Command' (复制登录口令). This is a classic phishing setup: a non-Google domain impersonating a Google product to capture credentials or session tokens, using a redirect to obscure the attacker's primary infrastructure and targeting Chinese-language users.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Thursday, September 10, 2026

Same data as JSON: /api/zone/domain/xn--drry38h.lol. This page is not indexed by search engines and does not link to the site it describes.