Security Scan Report: modules.wearehearken.com

Redirected to: https://ems.wearehearken.com/identities/sign_in#

Submitted: Mar 7, 2026, 2:31:16 PMCompleted: Mar 7, 2026, 2:32:01 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 2 countries across 6 domains to perform 14 HTTP transactions. The main domain is ems.wearehearken.com and was registered NaN years ago.

Submitted URL: https://modules.wearehearken.com

Effective URL: https://ems.wearehearken.com/identities/sign_in#Redirected

The Cisco Umbrella rank of the primary domain is #166,406 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

Page mimics Twitter and harvests credentials on a low‑ranked domain; likely a phishing site.

Risk Factors
Brand impersonation (Twitter) on a low‑ranked domain
Cross‑origin credential collection (email/password)
Low Cisco Umbrella ranking for brand claim
Domain age information unavailable

Details

Page Title

Hearken

Scan Type

public

Language

🇺🇸

English

(46% confidence)

Category

social media network

(94%)

Domain Information

The domain name 'modules.wearehearken.com' uses the commercial generic top-level domain (.com) with subdomain 'modules'. The core label 'wearehearken' covers 12 characters containing six vowels alongside six consonants. Segmentation suggests three words: we, are, hearken. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://modules.wearehearken.com

Page Load Overview

5.34s
Total Load Time
40
HTTP Requests
23
Domains
64 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:46%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:46%
Script Type:Latin
Text Length:611 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network94% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
94%
technology software
56%
healthcare medical
55%
government public service
54%
blog personal website
51%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1023.45.108.190Frankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
6104.16.137.209United States
63.167.227.106United States
AS16509Amazon.com, Inc.
618.66.147.8United States
618.173.205.62United States
AS16509Amazon.com, Inc.
6162.247.243.39United States
AS54113Fastly, Inc.
406--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DFF23A8678E2A4B317B345D9F1379341B2215063298DC860B7DE8EA92FC2DC69173E7C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:B1B1V2pQ8LDKt5p7Z5Uz9yzzxoZMnEFBgi4IQpfH6w7BR3WMgglttH5EQqD67mMB:Nr8o5PkMnOkZaUEAvmjNDW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:36224:T8PAhBYGB/KIUESShDVYGAAUZgQEkgU2AjzJpoaZ4EBDgYKsKBQAJASIBhFBUhYwZFiBFEVQOJyEcQgFBQykFaGJbNkLlBUA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000ffffe7ffff00
Perceptual Hash:f3a458a5728d58a7
Difference Hash:8c0c184c4c304a88
Wavelet Hash:0000e7e7e7ffed00
Color Hash:#3a783a

Scan History

Scan history not available

Unable to load historical scan data