Security Scan Report: sf16-website-login.neutral.ttwstatic.com

Submitted: Nov 26, 2025, 12:10:31 AMCompleted: Nov 26, 2025, 12:13:33 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is sf16-website-login.neutral.ttwstatic.com and was registered NaN years ago.

Submitted URL: https://sf16-website-login.neutral.ttwstatic.com/

The Cisco Umbrella rank of the primary domain is #5,474 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 95%

7
Risk Score

Site is high‑risk due to malicious primary domain and deceptive login subdomain.

Risk Factors
Primary domain flagged as malicious Indicators of Compromise
Subdomain mimics an authentication service (contains "login")
Lack of visible content may indicate hidden malicious behavior
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

malicious

(64%)

Domain Information

Domain 'sf16-website-login.neutral.ttwstatic.com' uses the commercial generic top-level domain (.com) with subdomain 'sf16-website-login.neutral'. The registrable portion 'ttwstatic' spans 9 characters split between 2 vowels and 7 consonants. It segments into three words: t, tw, static. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sf16-website-login.neutral.ttwstatic.com/

Page Load Overview

0.20s
Total Load Time
2
HTTP Requests
1
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:816 chars
Detector Agreement:100%

Website Classification

Primary Category

malicious64% confidence
Type: static
Method: ml+structural

All Detected Categories

malicious
64%
other
59%
suspicious phishing
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
22.22.50.125Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
12.22.50.136Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
22--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T185A0128E20A30015483073C40CC02220081553C420429640BBC295E46C04216CC071A0

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3:PouVIZxAhtvxLrbUApFwSqbvvoz:haxAhdxb5wSqQz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:f01e59a41d4721ddfdad557739d39a0b

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:87070707070f1f7f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#2dd2a9

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data