Security Scan Report: gre.ssffaa4.xyz

Redirected to:
https://2026-09-15.urldance.com/english?ssffaa4.xyz
Site favicon
Submitted: Sep 15, 2026, 2:47:36 AMCompleted: Sep 15, 2026, 2:48:48 AMpubliccompleted

This website contacted 7 IPs in 3 countries across 6 domains to perform 10 HTTP transactions. The main domain is 2026-09-15.urldance.com and was registered 26 years ago.

Submitted URL: https://gre.ssffaa4.xyz

Effective URL:

https://2026-09-15.urldance.com/english?ssffaa4.xyz
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Malware-linked domain (Vidar infostealer, multi-feed) serving a password gate via cross-domain redirect — do not enter any credentials.

Risk Factors (4)
Vidar infostealer associated with the primary domain (multi-feed corroboration)
Suspicious password-only authorization gate with urgent social-engineering wording
Cross-domain redirect to an unrelated registrable domain before serving content
Dynamic JavaScript code generation (eval/Function) on malware-flagged infrastructure
Domain age information unavailable

Details

Page Title

Resource Library - Premium Content, Secure Access

Scan Type

public

Domain Name Analysis

Domain 'gre.ssffaa4.xyz' uses the open generic top-level domain (.xyz), featuring subdomain 'gre'. The second-level label 'ssffaa4' is 7 characters long holding two vowels versus four consonants; it also includes one digit. Tokenizing the label suggests 5 words: s, s, ffa, a, 4. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gre.ssffaa4.xyz

Page Load Overview

43.08s
Total Load Time
58 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:x-default
Text Length:261 chars
Detector Agreement:100%
Language mismatch: Declared as x-default but detected as en

Website Classification

Primary Category

adult content53% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
53%
news media journalism
38%
government public service
36%
documentation technical
36%
cryptocurrency blockchain
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4156.225.108.41Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1156.225.108.43Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
154.215.31.113Aws · CLOUDSan Jose, California, United States
AS16509Amazon.com, Inc.
1156.225.108.42Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1183.240.98.228China
AS56040China Mobile communications corporation
1125.74.108.43China
AS141998China Telecom
1183.60.255.95China
AS4134Chinanet
107--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T142912D3041F8153F949281C86A39E76BBAD1D84BDA1F4100B6FC5BA44F87EC2DC37258

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:CkbEpKm/dTu8xR8xR8xR8xsq5qXCEL5CdJrAYjlMJHbSdR2n5Tn9sz5mXw+Cfzlf:CkMK+Fx5tFTBSLoEmuz7A102u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4440:wAQAxAMgMAgBgACACSIgBQACgAJBQAACQBApQAABVIoIQwAMIMBiAgEgIQIYABQJEAwghAIREoAJQIACQDAAACQpIBNEQEII

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0019191b1f1f1f07
Perceptual Hash:88397366669d9933
Difference Hash:9fb3b3b3b3b3f3ff
Wavelet Hash:01191b1b1f1f1f1f
Color Hash:#86372d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data