Security Scan Report: xcat2026.com

Redirected to:
https://xcat2026.com/auth/login?callback=%2Fuser%2Fticket
Site favicon
Submitted: Sep 12, 2026, 7:24:45 AMCompleted: Sep 12, 2026, 7:25:07 AMpubliccompleted

This website contacted 8 IPs in 4 countries across 6 domains to perform 27 HTTP transactions. The main domain is xcat2026.com and was registered 10 years ago.

Submitted URL: http://xcat2026.com/user/ticket

Effective URL:

https://xcat2026.com/auth/login?callback=%2Fuser%2Fticket
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Page impersonates Telegram, collects login credentials on a 3‑day‑old unranked domain – confirmed phishing scam.

Risk Factors
Brand impersonation (Telegram) on unrelated domain
Newly registered domain (<7 days)
Credential harvesting form
Unranked domain in Cisco Umbrella
Domain age information unavailable

Details

Page Title

喵了个咪 · XCAT · 学习助理 | Secured Private Networks

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'xcat2026.com' is registered. Count 8 characters in 'xcat2026' holding 1 vowel versus three consonants; it also includes 4 digits. Splitting it apart reveals 3 words: xc, at, 2026. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://xcat2026.com/user/ticket

Page Load Overview

2.90s
Total Load Time
786 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-cn
Text Length:307 chars
Detector Agreement:67%

Website Classification

Primary Category

social media network73% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
73%
education learning
55%
technology software
35%
adult content
32%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.17.6.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3185.111.111.158Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
3104.17.5.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
343.159.108.100Singapore
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
343.159.109.100Singapore
3149.154.167.99Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
278--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1933168A35565200D3A00F34CE9547078CD17450FDEABA950F9AE023DAFF2AB7849793D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:kup2EjzvCVzvTVzv4VJwM+JedK0CHJtXCZc:kuHzaVzrVzQVJwvJedKLHJFCZc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1697:BAAIFAAIBgAAAAQQAAwAAABCgBgAABAAAQIAAAAAAABQAAAAAAAAkBCgAAIAAEIEAAACEEAAEQAAECgAAAAAAAxAIAAYAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:8c7c33db33cd3230
Difference Hash:31b3b3b3b3b3b331
Wavelet Hash:3939393939393939
Color Hash:#2dd232

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data