Security Scan Report: zhenglu-dcmdui38nl.edgeone.dev

Site favicon
Submitted: May 9, 2026, 4:21:38 PMCompleted: May 9, 2026, 4:23:01 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 2 countries across 4 domains to perform 161 HTTP transactions. The main domain is zhenglu-dcmdui38nl.edgeone.dev and was registered NaN years ago.

Submitted URL: https://zhenglu-dcmdui38nl.edgeone.dev/guiyangtang.html

AI Security Verdict

Moderate Risk

Confidence: 78%

5
Risk Score

The site shows strong malicious network activity (C2 beacon, data exfiltration) despite lacking forms, indicating a likely malware distribution host.

Risk Factors
Unranked domain on a hosting platform
Unknown subdomain age (could be brand‑new)
Critical IDS alerts indicating malware C2 and data exfiltration
High JavaScript obfuscation score
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

healthcare medical

(91%)

Domain Information

Domain 'zhenglu-dcmdui38nl.edgeone.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'zhenglu-dcmdui38nl'. The core label 'edgeone' covers 7 characters split between 4 vowels and three consonants. Splitting it apart reveals 2 words: edge, one. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zhenglu-dcmdui38nl.edgeone.dev/guiyangtang.html

Page Load Overview

5.41s
Total Load Time
158
HTTP Requests
4
Domains
6.8 MB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:4,372 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical91% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
91%
government public service
80%
adult content
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
41208.95.112.1United States
AS53334Total Uptime Technologies, LLC
39142.251.20.95United States
AS15169Google LLC
3943.174.247.29Singapore
39142.251.110.94United States
AS15169Google LLC
1584--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12EF23070A483A8374A335CDAA07B5B3FA1EE921DDD538595C3FCC39807C9C66FA22941

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:cducGd7B8o7J0JY4NYEYj+lcA1AYV3TwYZ5IYjck2NYEOUYEh0RYrzhy:uGd7B86J0JY4NYEYj+lcA1AYV3TwYZ5T

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:37250:z+ECrgMEOEaDIxFgSAAAA2VoCCn0gJkKcIA4AKEAvASQULSRTFASBOSQBkAMQMRmJiaORq4pyJnDAVgWDniQJkMowNAUAiaC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00003fc3ffffffff
Perceptual Hash:a80806176dfdd793
Difference Hash:f7f3790303600c4c
Wavelet Hash:00000081f3ffffff
Color Hash:#6240bf

Scan History

Scan history not available

Unable to load historical scan data