Security Scan Report: www.northbaltimore.gov

Submitted: Nov 15, 2025, 7:40:27 PMCompleted: Nov 15, 2025, 7:41:48 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 0 countries across 1 domain to perform 28 HTTP transactions. The main domain is northbaltimore.gov and was registered NaN years ago.

Submitted URL: https://www.northbaltimore.gov/

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

Likely phishing site impersonating North Baltimore city services

Risk Factors
Brand impersonation on a non‑established domain
Recent domain registration (130 days) for a .gov‑style site
Unranked domain (not in top 1 M) despite claiming official city branding
Suspicious OCR text suggesting fraudulent emergency update request
Domain age information unavailable

Details

Page Title

Home | Village of North Baltimore

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government

(95%)

Domain Information

You're looking at domain 'www.northbaltimore.gov' on the United States government-restricted top-level domain (.gov) and includes subdomain 'www'. The second-level label 'northbaltimore' is 14 characters long with 5 vowels and nine consonants. Splitting it apart reveals 2 words: north, baltimore. Average segment length settles at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.northbaltimore.gov/

Page Load Overview

62.92s
Total Load Time
28
HTTP Requests
1
Domains
685 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,594 chars
Detector Agreement:100%

Website Classification

Primary Category

government95% confidence
Type: dynamic
Method: structural

All Detected Categories

government
95%
corporate
50%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1023.185.0.3UnknownUnknown
92620:12a:8000::3UnknownUnknown
92620:12a:8001::3UnknownUnknown
283--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T129C3A6214464383FA69F0BC06AF9B74AE3A2B247D9C54944B6FCDF960FC6C52BC4605E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:DwtAaGE9K959nWfAWF8mMWgRfBpezTllkdWasdWjZjtM26WuyjlG1H:Dk9yjWPZgpezTDvWvZuyjlG1H

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:123966:FAsIBSgGnlqIoCUKgUAoQJxIBI9CCOECUEcAFEQaFBQXQa4mIywGg4Iw0RHDlQQBGULIAhBKRCIWUApZXDglEFdHhAKBQYBg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff8f87000000
Perceptual Hash:bfda406c3ee1618c
Difference Hash:2360493c3f2e8a27
Wavelet Hash:ffffff8f07000000
Color Hash:#e0946c

Scan History

Scan history not available

Unable to load historical scan data