Security Scan Report: idref.fr

Redirected to:
https://www.idref.fr/
Site favicon
Submitted: May 19, 2026, 4:22:24 AMCompleted: May 19, 2026, 4:24:16 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 7 domains to perform 69 HTTP transactions. The main domain is idref.fr and was registered NaN years ago.

Submitted URL: https://idref.fr

Effective URL: https://www.idref.fr/Redirected

The Cisco Umbrella rank of the primary domain is #237,319 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 78%

4
Risk Score

The site shows signs of possible malware activity (C2 beacon) despite being well‑established and lacking phishing forms; treat as suspicious and avoid use.

Risk Factors
Critical IDS alert indicating possible malware command‑and‑control activity
Highly obfuscated JavaScript code
Low domain reputation ranking
Safety Factors
No forms collecting credentials or payments
Brand name matches the domain (self‑branding, not impersonation)
Long‑standing domain registration (over 15 years)
Domain age information unavailable

Details

Page Title

IdRef - Identifiants et référentiels pour l'Enseignement supérieur et la Recherche

Scan Type

public

Language

🇫🇷

French

(48% confidence)

Category

adult content

(38%)

Domain Information

Domain 'idref.fr' uses the French country-code top-level domain (.fr) with no subdomain. The second-level label 'idref' is 5 characters long with 2 vowels and three consonants. Word splitting yields two words: id, ref. Median word length comes out to 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://idref.fr

Page Load Overview

42.08s
Total Load Time
67
HTTP Requests
7
Domains
456 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:48%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:48%
Script Type:Latin
Text Length:3,147 chars
Detector Agreement:80%

Website Classification

Primary Category

adult content38% confidence
Type: spa
Method: ml+structural

All Detected Categories

adult content
38%
government public service
28%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15142.251.14.94United States
AS15169Google LLC
13151.101.194.137United States
AS54113Fastly, Inc.
13142.251.14.95United States
AS15169Google LLC
13104.18.11.207United States
AS13335Cloudflare, Inc.
13193.52.26.110Paris, Île-de-France, France
AS2200Renater
675--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13CD2E7145C9ECC6A610209D1E8E4FE2C107F4FA8D3025888F5FF967673CBE949A136E9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:eKlLdC4Vt5LcS1wFcNGSnpH1sv7q+keC4R2A22+H:tLdC4n5AS1wFc9JQd1WH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:30011:0ytCJITSYgQiFEMJEiggABROxIaiR3AwEkg6ARUAMoegQFYMSCMEwCkJkmw5oBKQAZtOpEaokaLXhCHQb8UIBaCGEARIC0Ag

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Scan History

Scan history not available

Unable to load historical scan data