Flagged newborn domains, Wednesday, October 7, 2026
9,487 names at tier low or above, highest score first.
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
punycode name “벳위즈사이트 scripts=HANGUL”random-looking name “H=3.98”
punycode name “英博体育 scripts=CJK”random-looking name “H=3.77”
punycode name “따뜻한여사 scripts=HANGUL”random-looking name “H=3.73”
punycode name “오케이사이트 scripts=HANGUL”random-looking name “H=3.82”
punycode name “包装产业 scripts=CJK”random-looking name “H=3.66”
punycode name “행사대여 scripts=HANGUL”random-looking name “H=3.77”
punycode name “대출디비클릭 scripts=HANGUL”random-looking name “H=4.11”
punycode name “대림익스프레스 scripts=HANGUL”random-looking name “H=4.22”
punycode name “무대시스템 scripts=HANGUL”random-looking name “H=3.79”
punycode name “꼬춘쿠키 scripts=HANGUL”random-looking name “H=3.62”
punycode name “浙江供销社 scripts=CJK”random-looking name “H=3.78”
punycode name “세븐럭평생 scripts=HANGUL”random-looking name “H=3.95”
punycode name “数字资产标识 scripts=CJK”random-looking name “H=4.19”
punycode name “资产权属标识 scripts=CJK”random-looking name “H=3.91”
punycode name “资产标识 scripts=CJK”random-looking name “H=3.77”
punycode name “四大系列减速机 scripts=CJK”random-looking name “H=4.10”
punycode name “호텔문지방 scripts=HANGUL”random-looking name “H=4.06”
punycode name “米哈游法务部 scripts=CJK”random-looking name “H=4.09”
punycode name “重庆火锅 scripts=CJK”random-looking name “H=3.64”
page impersonates a brand “PayPal”
TLD with a high abuse rate “cfd”login form “has_form+login words”
TLD with a high abuse rate “cfd”login form “has_form+login words”
TLD with a high abuse rate “cfd”login form “has_form+login words”
TLD with a high abuse rate “cfd”login form “has_form+login words”
TLD with a high abuse rate “work”login form “has_form+login words”
lure words (login, verify, secure…) “claim,claims”many hyphens “4”very long name “34”
page impersonates a brand “PayPal”
TLD with a high abuse rate “xyz”page pushes urgent payment “act Now”
page impersonates a brand “USPs”
page impersonates a brand “Binance”
page impersonates a brand “Binance”
TLD with a high abuse rate “top”login form “has_form+login words”
page impersonates a brand “IRS”
page impersonates a brand “DHL”
page impersonates a brand “BINANCE”
TLD with a high abuse rate “icu”page pushes urgent payment “act now”
page impersonates a brand “PayPal”
page impersonates a brand “PayPal”
page impersonates a brand “PayPal”
page impersonates a brand “PayPal”
page impersonates a brand “Amazon Prime”
page impersonates a brand “Amazon Prime”
TLD with a high abuse rate “xyz”login form “has_form+login words”
page impersonates a brand “DHL”
page impersonates a brand “Binance”
page impersonates a brand “Microsoft 365”
page impersonates a brand “NETFLIX”
page impersonates a brand “Binance”
TLD with a high abuse rate “cfd”page pushes urgent payment “act Now”
brand in the name “lineme”TLD with a high abuse rate “xyz”
Same data as JSON: /api/zone/risk?day=2026-10-07&tier=low. Screenshots and the model's reasoning are on each domain's evidence page.