Security Scan Report: fishymatto.com

Redirected to:
https://fishymatto.com/
Submitted: Sep 28, 2026, 7:50:39 AMCompleted: Sep 28, 2026, 7:51:23 AMpubliccompleted

This website contacted 1 IP in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is fishymatto.com and was registered 3 months ago.

Submitted URL: http://fishymatto.com/

Effective URL:

https://fishymatto.com/
Redirected

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Amateur astronomy/telemetry-themed site with its own branding, no forms, no malware and no Indicators of Compromise. Only weak priors (unranked, 108 days old) and an uncorroborated ML phishing label — no concrete malicious signal.

Risk Factors (3)
Unranked domain with no established reputation
Machine-learning classifier assigns a 77% 'phishing scam' label, though it is uncorroborated by any form, credential field, or threat-intel hit
Heavy 'restricted / classified / clearance (403)' theme could be misread as access-gating, and no visible operator identity or contact details
Safety Factors (5)
No forms of any kind (0 total) — no credential, login, or payment collection
No disguised password fields, no unicode confusion
No Indicators of Compromise, no JavaScript malware, no IDS alerts
No third-party script hosts, no cross-origin scripts, no credential exfiltration
Self-branded amateur observatory content with no impersonation of any real organisation
Domain age information unavailable

Details

Page Title

Telemetry Restricted | Nightwell Observatorysecondary capture

Scan Type

public

Domain Name Analysis

Domain 'fishymatto.com' uses the commercial generic top-level domain (.com). The registrable portion 'fishymatto' spans 10 characters containing three vowels alongside 7 consonants. Segmentation suggests two words: fishy, matto. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://fishymatto.com/

Page Load Overview

0.23s
Total Load Time
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,903 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam77% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

phishing scam
77%
technology software
72%
documentation technical
69%
adult content
34%
government public service
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3185.212.109.6Novi Travnik, Federation of Bosnia and Herzegovina, Bosnia and Herzegovina
AS200698Globalhost d.o.o.
31--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13322D70AA8C1213AB03394EEEE71238D6194502BF523C610F5DF958ACF4D17B7967F89

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:CFp6lwYdPuqBF+djRJegTabpbQ1DhMQ8r6gRzX:C/6lTmhTaNs1o6UX

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10850:qhBGAQAUIB7iQgAhAA3AzQLAIIN/8UQ0QBGYCgaRERtAknAAqIwK2IA+40zw5QCYTkMQhkAAgNAhiEIYSMAQxAYAQgAagJqF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0303030303030303
Perceptual Hash:ad56565656525a5a
Difference Hash:c7c7d7c7c7e7dbd7
Wavelet Hash:7f3f032303232f2b
Color Hash:#c1e06c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data