Security Scan Report: or3k-51808.portmap.host

Redirected to:
https://portmap.io/
Submitted: Sep 15, 2026, 2:47:41 AMCompleted: Sep 15, 2026, 2:48:48 AMpubliccompleted

This website contacted 38 IPs in 3 countries across 22 domains to perform 81 HTTP transactions. The main domain is portmap.io and was registered 22 years ago.

Submitted URL: https://or3k-51808.portmap.host

Effective URL:

https://portmap.io/
Redirected

AI Security Verdict

High Risk

Confidence: 60%

7
Risk Score

Legitimate Portmap.io port-forwarding page reached via cross-domain redirect; no forms or impersonation. Only a single-source unverified XWorm hit on the redirecting entry host and generic abuse-reputation tags — no concrete content signal.

Risk Factors
Sole content-malware-typed indicator is a single-source, unverified XWorm report against the redirecting entry subdomain, not corroborated by any second feed
The service itself (port forwarding/tunneling) carries a generic 'port proxy (suspicious)' reputation tag and triggers tunneling-related IDS categorization, indicating it is commonly abused as an anonymizing relay
Domain age information unavailable

Details

Page Title

Portmap.io - free port forwarding solution

Scan Type

public

Domain Name Analysis

You're looking at domain 'or3k-51808.portmap.host' on the .host top-level domain with subdomain 'or3k-51808'. The second-level label 'portmap' is 7 characters long split between two vowels and 5 consonants. Segmentation suggests two words: port, map. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://or3k-51808.portmap.host

Page Load Overview

40.61s
Total Load Time
3.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:7,815 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software34% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
34%
social media network
29%

Detected Features

Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.20.155Google · CDNUnited States
AS15169Google LLC
2193.161.193.99Russia
AS198134Ooo Getwifi
2142.251.150.119Google · CDNUnited States
AS15169Google LLC
2172.67.75.33Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
22.16.204.144Akamai · CDNHamburg, Free and Hanseatic City of Hamburg, Germany
AS20940Akamai International B.V.
2172.217.114.4Google · CDNUnited States
AS15169Google LLC
2142.251.110.154Google · CDNUnited States
AS15169Google LLC
8138--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B56135074D968A0422202912F8927405C8F6770F952CA8F1F95D827E2FD0BEAD077D6E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nfqdBXGPIEBBZi3/brwbZ3ErVCrE1ne1rVfrqZNZ89ZtyZHwAF8zRSYSr/u+CVI:nmATZzDBfXwwFIJjL

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3406:AlCAAACAAEAKAAhAFEAAAgAEFEkAACEIAAEQJAMDQCEQsBAAABCEBAUFCKAABgAxAAAWEAKMAACggAEAACOCBAAQACAAAgQA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:d3003c3c3cc7ffff
Perceptual Hash:8a0af4e48f87a5cb
Difference Hash:a7b1696969961661
Wavelet Hash:00003c3c3cc3ffff
Color Hash:#60ac53

Scan History

Scan history not available

Unable to load historical scan data