Security Scan Report: id.dhnet.be

Redirected to:
https://auth.piano.io/u/login/identifier?state=hKFo2SA2aFFCMkQ5c1M5enZ...
Site favicon
Submitted: May 19, 2026, 6:27:39 PMCompleted: May 19, 2026, 6:29:17 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 4 HTTP transactions. The main domain is auth.piano.io and was registered NaN years ago.

Submitted URL: https://id.dhnet.be

Effective URL: https://auth.piano.io/u/login/identifier?state=hKFo2SA2aFFCMkQ5c1M5enZOYlJvVlF5V3Y2dmhGQmN1Vi16aqFur3VuaXZlcnNhbC1sb2dpbqN0aWTZIE54ZGg3YjRIbVJJRXd3SlNfQmROakJ2Mjd0anE5QVJxo2NpZNkgdG5IZTUyaWpRcGlURG9nYVhMS1dMNmU3UmlXd2p1Z3QRedirected

The Cisco Umbrella rank of the primary domain is #230,672 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 85%

5
Risk Score

The site likely impersonates the Piano brand to harvest credentials; avoid and report as a scam.

Risk Factors
Brand impersonation on low‑ranking domain
Credential collection form on unrelated domain
Multiple redirects to a different domain
Low Cisco Umbrella ranking for a site claiming a major brand
Safety Factors
Domain age > 25 years (well‑established)
No malicious Indicators of Compromise detected
No JavaScript malware patterns or IDS alerts
Established domain (9513 days old) with no strong malicious indicators — risk clamped from 8 to 5
Domain age information unavailable

Details

Page Title

auth.piano.io

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'id.dhnet.be' uses the Belgian country-code top-level domain (.be) with subdomain 'id'. The core label 'dhnet' covers 5 characters holding one vowel versus 4 consonants. Tokenizing the label suggests 2 words: dh, net. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://id.dhnet.be

Page Load Overview

8.81s
Total Load Time
9
HTTP Requests
4
Domains
328 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:124 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5172.64.153.85United States
AS13335Cloudflare, Inc.
4104.16.143.111United States
AS13335Cloudflare, Inc.
92--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BD048F773296063986558498F05B43099F20B143F50AC8BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:8/Qho9PKBb9Js3q9Jzbs6tlg1ySBKwdQ9gcoIsPW2bMy8OldC:NhoC9JSqzzbs6okSjggcpsO2eAo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:185909:EtiIikDCJEAUIBE4qhYYBpUKWAVIkSZAjCIAeHBQAJJRMps3UGOyjAhxTdUIOBIAEGAhQAhoiaSwUQYBhEHgIAgi4ESuGA4q

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffdfc3c3ffffffff
Perceptual Hash:b333cccccc23338b
Difference Hash:00100c1c00000000
Wavelet Hash:ffdfc3c300000000
Color Hash:#931f7a

Other Hashes

Crop Resistant:00100c1c00000000

Scan History

Scan history not available

Unable to load historical scan data