Security Scan Report: www.couriermail.com.au

Redirected to: https://www.couriermail.com.au/subscribe/news/1/?sourceCode=CMWEB_WRE170_a&dest=https%3A%2F%2Fwww.couriermail.com.au%2Fnews%2Fqueensland%2Ftonga-v-samoa-could-set-rugby-league-record-at-suncorp-stadium%2Fnews-story%2Fcee3b14db9944fbbbd886cf0cddb1dd0&memtype=anonymous&mode=premium&v21=GROUPA-Segment-2-NOSCORE

Site favicon
Submitted: Oct 26, 2025, 5:35:21 AMCompleted: Oct 26, 2025, 5:36:58 AMpubliccompleted
Loading additional data...

Summary

This website contacted 220 IPs in 7 countries across 82 domains to perform 345 HTTP transactions. The main domain is couriermail.com.au and was registered NaN years ago.

Submitted URL: https://www.couriermail.com.au/news/queensland/tonga-v-samoa-could-set-rugby-league-record-at-suncorp-stadium/news-story/cee3b14db9944fbbbd886cf0cddb1dd0

Effective URL: https://www.couriermail.com.au/subscribe/news/1/?sourceCode=CMWEB_WRE170_a&dest=https%3A%2F%2Fwww.couriermail.com.au%2Fnews%2Fqueensland%2Ftonga-v-samoa-could-set-rugby-league-record-at-suncorp-stadium%2Fnews-story%2Fcee3b14db9944fbbbd886cf0cddb1dd0&memtype=anonymous&mode=premium&v21=GROUPA-Segment-2-NOSCORERedirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

The site is a fraudulent Courier Mail clone using redirects and payment prompts; treat as confirmed phishing scam.

Risk Factors
Brand impersonation on an unranked, newly‑registered domain
Circular redirect indicating possible URL manipulation
Excessive redirect chain (11 redirects)
Payment collection on a domain with low reputation
Domain age only 225 days (recent registration)
Domain age information unavailable

Details

Page Title

Couriermail.com.au | Subscribe to The Courier Mail for exclusive stories

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(66%)

Domain Information

Domain 'www.couriermail.com.au' uses the Australian country-code top-level domain (.com.au), featuring subdomain 'www'. The registrable portion 'couriermail' spans 11 characters containing 6 vowels alongside five consonants. Word splitting yields two words: courier, mail. Average segment length settles at 5.5 characters. 'courier' most often appears in English. You may catch it in Chinese (Pinyin) and French as well. Net impression: English phrase.

Screenshot

Security scan screenshot of https://www.couriermail.com.au/news/queensland/tonga-v-samoa-could-set-rugby-league-record-at-suncorp-stadium/news-story/cee3b14db9944fbbbd886cf0cddb1dd0

Page Load Overview

12.72s
Total Load Time
345
HTTP Requests
82
Domains
7.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-AU
Text Length:3,271 chars
Detector Agreement:100%

Website Classification

Primary Category

other66% confidence
Type: spa
Method: ml+structural

All Detected Categories

other
66%
e-commerce
57%
legitimate website
56%
malicious
41%
suspicious phishing
39%

Detected Features

Articles
Products
OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
126199.127.207.190United States
36192.0.66.58San Francisco, California, United States
AS2635AUTOMATTIC
2299.84.152.18United States
AS16509AMAZON-02
2223.206.208.104Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
19184.30.22.145Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
18142.250.185.131United States
AS15169GOOGLE
153.171.214.63United States
AS16509AMAZON-02
12172.217.18.14United States
AS15169GOOGLE
1054.187.159.182Boardman, Oregon, United States
AS16509AMAZON-02
1023.206.208.183Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
345220--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13B244C61F80410B75E3F05217488B7AF51178E2BE5214EFEB1AF128857CCDEB6693B1A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:QDvtwR842UbHsaDImBHqR733/J6qvxP2lWX9:WvmR84zHsaDzBHqx33/J6J6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:218222:wABw+VVIE4qVA0WgDjyBAJI6KQBSCIhkKVii5AEmQSxIahQCIHJBokIIiYkACQDC4RYGYLABqdQH4ecJsCcUqweK0B5qQjEH

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff00000000ffffff
Perceptual Hash:ca12edb26d92ed12
Difference Hash:4ce97968cd0c2d23
Wavelet Hash:ff00000000ffffff
Color Hash:#6ce096

Scan History

Scan history not available

Unable to load historical scan data