Security Scan Report: k8online4.bond

Redirected to:
https://winrolla1.com/de/registration
Submitted: Apr 25, 2026, 4:27:39 PMCompleted: Apr 25, 2026, 4:29:28 PMpubliccompleted
Loading additional data...

Summary

This website contacted 17 IPs in 4 countries across 14 domains to perform 245 HTTP transactions. The main domain is winrolla1.com and was registered NaN years ago.

Submitted URL: http://k8online4.bond/registration/?id=pioneerslotscasino

Effective URL: https://winrolla1.com/de/registrationRedirected

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

The site shows strong brand‑impersonation signals on an unranked domain with many redirects and heavily obfuscated JavaScript, warranting high risk.

Risk Factors
Unranked domain with brand claim
Multiple redirects (5)
High JavaScript obfuscation score
External domains from obscure resolvers (seondnsresolve.com)
Gambling brand on a non‑established domain
Domain age information unavailable

Details

Page Title

Online casino and online betting site - Winrolla Casino

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

corporate

(50%)

Domain Information

Within the .bond top-level domain, 'k8online4.bond' is registered and has no subdomain. The core label 'k8online4' covers 9 characters containing three vowels alongside four consonants, along with two digits. Tokenizing the label suggests four words: k, 8, online, 4. Average segment length settles at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://k8online4.bond/registration/?id=pioneerslotscasino

Page Load Overview

3.21s
Total Load Time
245
HTTP Requests
14
Domains
454 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de-de
Text Length:15,876 chars
Detector Agreement:50%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
21104.21.16.38United States
AS13335Cloudflare, Inc.
1452.212.22.204Dublin, Leinster, Ireland
AS16509Amazon.com, Inc.
1454.74.124.88Dublin, Leinster, Ireland
AS16509Amazon.com, Inc.
14185.207.196.69Marshall Islands
AS213846Nalmi Limited
14185.207.199.218Marshall Islands
AS213846Nalmi Limited
14104.18.95.41United States
AS13335Cloudflare, Inc.
14185.207.197.175Marshall Islands
AS213846Nalmi Limited
1454.74.59.74Dublin, Leinster, Ireland
AS16509Amazon.com, Inc.
1488.214.195.16United Kingdom
AS46636NatCoWeb Corp.
14142.250.154.97United States
AS15169Google LLC
24517--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16FB4A62D67B9683D0BACD3859D309AAAAE7E4F80817091F571BEC92B034CE65D43F05D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:OSiLSijSidSikSiZSiASihSinSiBSihSifSiFSioSiISijtnSi6SizSi6SiMSife:UtT9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:499626:YlSMN4ghARBgAYygY+kkDBrUBYEOCEwoku4FBkABCAaEfBRBcKBNhai0DAAQRKAIoANmVSCDAkiIMGcSYwBiwApYCYLQCTgw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:d33038303020243c
Perceptual Hash:c76d926d98b26992
Difference Hash:056242624a424d6d
Wavelet Hash:dfb9b830b0a034bd
Color Hash:#b7e06c

Other Hashes

Crop Resistant:056242624a424d6d

Scan History

Scan history not available

Unable to load historical scan data