Security Scan Report: aycagl.com

Submitted: Apr 27, 2026, 8:31:54 AMCompleted: Apr 27, 2026, 8:33:02 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 20 HTTP transactions. The main domain is aycagl.com and was registered NaN years ago.

Submitted URL: https://aycagl.com/malware%20analysis/XWorm-Malware-Teknik-Analiz-Raporu-97204262733c/

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

New unranked site impersonates LinkedIn/GitHub, flagged as phishing with high confidence; treat as confirmed scam.

Risk Factors
New domain (<7 days) with high risk multiplier
Unranked domain claiming major brand logos
High JavaScript obfuscation score
ML phishing classification confidence 100%
Brand impersonation detection
Domain age information unavailable

Details

Page Title

XWorm Malware Teknik Analiz Raporu - aycagl

Scan Type

public

Language

🇹🇷

Turkish

(45% confidence)

Category

phishing scam

(100%)

Domain Information

You're looking at domain 'aycagl.com' on the commercial generic top-level domain (.com) while skipping any subdomain. The second-level label 'aycagl' is 6 characters long holding 2 vowels versus 4 consonants. Segmentation suggests three words: ay, ca, gl. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://aycagl.com/malware%20analysis/XWorm-Malware-Teknik-Analiz-Raporu-97204262733c/

Page Load Overview

1.15s
Total Load Time
21
HTTP Requests
2
Domains
5.0 MB
Total Size

Language Analysis

Primary Language

🇹🇷Turkish
Code: tr
Confidence:45%
Script:Latin
Direction:ltr

Detection Details

Language Code:tr
Detection Confidence:45%
Script Type:Latin
HTML Lang Attribute:en
Text Length:15,331 chars
Detector Agreement:80%
Language mismatch: Declared as en but detected as tr

Website Classification

Primary Category

phishing scam100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
100%
documentation technical
70%
technology software
44%

Detected Features

Search
OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11185.199.108.153United States
AS54113Fastly, Inc.
10104.18.40.68United States
AS13335Cloudflare, Inc.
212--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BAE22902F4E53067466752BAE2E4DB9FF60A4243E3208D41B6EDD289AFC1F6146F320C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:1IMrMXVLQMrMEx3LXAuFCpdmCXY9UmtEguF:1HA5/AEx3Lw6CpV+UNguF

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31779:RxFdcyArRA4wYx4mGEmNCQCAAouLUCEVQMQAVXIBmAYoIVi0AkhfA4tWBAAropADsRUiYGIAFc8ivsZgWoBc4MY8zDORCJMA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1c39381838183838
Perceptual Hash:8a723333353493dd
Difference Hash:b9e1f1f171717171
Wavelet Hash:0d79393939393939
Color Hash:#40bf99

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data