Security Scan Report: holiday-forever.cc

Redirected to:
https://www.gmx.net/consent-management/
Site favicon
Submitted: Sep 17, 2026, 7:47:46 AMCompleted: Sep 17, 2026, 7:48:28 AMpubliccompleted

This website contacted 5 IPs in 3 countries across 8 domains to perform 57 HTTP transactions. The main domain is gmx.net and was registered 14 years ago.

Submitted URL: https://holiday-forever.cc

Effective URL:

https://www.gmx.net/consent-management/
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Entry domain holiday-forever.cc is flagged as lummac2 malware by 3 corroborated feeds and redirects to the genuine GMX consent page. The final page is clean, but the malware-flagged origin host drives a HIGH_RISK rating.

Risk Factors
Primary/entry domain flagged as lummac2 malware by 3 corroborated intelligence feeds
Cross-domain redirect from a malware-flagged host to an unrelated legitimate site
HIGH severity IDS alert for .cc TLD DNS query
Domain age information unavailable

Details

Page Title

GMX - kostenlose E-Mail, Cloud, Nachrichten & Freemail

Scan Type

public

Domain Name Analysis

Within the .cc country-code top-level domain, 'holiday-forever.cc' is registered without a subdomain. The registrable portion 'holiday-forever' spans 15 characters split between six vowels and 8 consonants, along with 1 hyphen. Breaking it apart gives 2 words: holiday, forever. The median word length lands at seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://holiday-forever.cc

Page Load Overview

5.43s
Total Load Time
338 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:182 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software73% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
73%
documentation technical
64%
gambling betting
64%
government public service
52%
phishing scam
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1379.124.59.146Bulgaria
AS50360Tamatiya EOOD
11217.72.199.68Germany
AS8560IONOS SE
112.17.96.181Akamai · CDNVienna, Vienna, Austria
AS16625Akamai Technologies, Inc.
1123.52.180.183Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
11217.72.199.24Germany
AS8560IONOS SE
575--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T194A1B7F3A911C9751240A2E0A261F72D92A9F557FE80C8C4B6FC42507B85FEF68747E8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:x+yJuVUQYE2VCM7rpO97Q7vY4jC8poINKHLcCSv8KHBvVVG9kUMHUogUbqUMy5Dq:3QvYLVCM7rA97Qxr6WyzM0abzMg+Hsw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4984:FIgCIMUACgACKEBRGhKCACCAhACgBgSYAZBmwEgCAAgACEAQKUAAgAgjYUQhCEiYSIgHFoARIWgAAEYKERSCABAAoiEmBECA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3c3c3c3c3c3c3c3c
Perceptual Hash:9e66333b3e31292c
Difference Hash:6969716161697979
Wavelet Hash:3c3c3c3c3c3c3c3c
Color Hash:#6ce0a4

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data