Security Scan Report: bookingdotcomb2b.germany-2.evergage.com

Redirected to: https://bookingdotcomb2b.germany-2.evergage.com/ui/login.html

Site favicon
Submitted: Nov 25, 2025, 1:11:51 PMCompleted: Nov 25, 2025, 1:14:38 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 2 domains to perform 25 HTTP transactions. The main domain is bookingdotcomb2b.germany-2.evergage.com and was registered NaN years ago.

Submitted URL: https://bookingdotcomb2b.germany-2.evergage.com/

Effective URL: https://bookingdotcomb2b.germany-2.evergage.com/ui/login.htmlRedirected

The Cisco Umbrella rank of the primary domain is #3,207 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

High‑risk phishing site impersonating Salesforce login; do not enter credentials.

Risk Factors
Hidden password fields used for credential harvesting
Brand impersonation of Salesforce on an unrelated domain
Login page with numerous password fields on a domain that does not belong to the brand
DNS resolution failure (DNS_PROBE_FINISHED_NXDOMAIN) indicating possible malicious redirection tactics
Domain age information unavailable

Details

Page Title

Login | Salesforce Personalization

Scan Type

public

Domain Information

The domain name 'bookingdotcomb2b.germany-2.evergage.com' uses the commercial generic top-level domain (.com) and includes subdomain 'bookingdotcomb2b.germany-2'. The registrable portion 'evergage' spans 8 characters with four vowels and 4 consonants. Breaking it apart gives 2 words: ever, gage. Average segment length settles at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bookingdotcomb2b.germany-2.evergage.com/

Page Load Overview

0.43s
Total Load Time
25
HTTP Requests
2
Domains
544 KB
Total Size

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2335.157.176.137Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
335.158.191.110Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
335.157.40.137Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
3151.101.192.114San Francisco, California, United States
AS54113FASTLY
3151.101.128.114San Francisco, California, United States
AS54113FASTLY
3151.101.0.114San Francisco, California, United States
AS54113FASTLY
1151.101.64.114San Francisco, California, United States
AS54113FASTLY
257--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T104047E77329A063D86558498E05743099F20B143B50AC9BC7ABCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:7fQho9PKBb9JsE9RHCbZgRjFtSBaw9QWgceIszs2bMy8Oldm:khoC9J395CbZgLtSL3gcrsA2eA8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:183825:SSRBgiUBBQIBYCVgABlkIBhUkRC4B5bAszAQlZCjEpEEZATAQUZECGVMAytIoAgKhFCJmFgyBoBIggVDAk4kBADDwAGyygg6

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff7f0703fffffefc
Perceptual Hash:9229d2ad5e2d33d2
Difference Hash:c0c05a6b60000004
Wavelet Hash:7f7f07010f0f0f0c
Color Hash:#3a6f78

Other Hashes

Crop Resistant:c0c05a6b60000004

Scan History

Scan history not available

Unable to load historical scan data