Highscore 51 · flagged Monday, September 28, 2026

xn--fhqs8bgz6cgdlfu0awka.top

Appeared in the .top zone on Monday, September 28, 2026; by the end of that day the census found empty page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

punycode name
matched: 上海移远通信 scripts=CJK
+18
random-looking name
matched: H=4.19
+5
TLD with a high abuse rate
matched: top
+8
brand in page title, not in the name
matched: google
+20
Registrar
—
Nameserver provider
Nameservers
ns1.onclouddns.com, ns2.onclouddns.com
First-day state
empty page
HTTP status
200
Page title
Google
Has a form
no
Brand echoed
—

Model opinions

Second opinionlooks like abusetarget: Quectel (上海移远通信)confidence 55%· claude-opus-5-5

The punycode name decodes to 上海移远通信, the Chinese name of Shanghai Quectel Wireless Solutions, registered on a cheap .top TLD that the company is unlikely to own. It serves an empty page titled only 'Google' at a random path (/4sngzc), which looks like a cloaked brand-squat or redirector rather than a legitimate site. There is no form or credential capture, so this is not phishing.

First passsuspicioustarget: googleconfidence 41%· typesafe/jev-latest

typesafe first pass (gate 0.4): p=suspicious:0.51 abuse:0.39 benign:0.07 | impersonates=0.61 credential=0.08 parked=0.78 evidence=1.7 | target=google:0.89

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/xn--fhqs8bgz6cgdlfu0awka.top. This page is not indexed by search engines and does not link to the site it describes.