Security Scan Report: www.bqzl36.vip

Redirected to:
https://www.h593h3.vip:9122/register57473?i_code=73104968
Site favicon
Submitted: Sep 18, 2026, 6:47:40 AMCompleted: Sep 18, 2026, 6:48:22 AMpubliccompleted

This website contacted 5 IPs in 4 countries across 4 domains to perform 39 HTTP transactions. The main domain is h593h3.vip and was registered 1 year 2 months ago.

Submitted URL: https://www.bqzl36.vip

Effective URL:

https://www.h593h3.vip:9122/register57473?i_code=73104968
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Gambling-brand impersonation posing as Kaiyun Sports/Real Madrid official partner; collects account credentials on an unrelated, unranked domain with a formbook threat-intel hit. Avoid.

Risk Factors
Impersonation of a known gambling brand (开云体育/Kaiyun Sports) and Real Madrid partnership claims
Credential-collecting registration form with two password fields on a non-official domain
Cross-domain redirect to a different registrable domain with a non-standard port (9122)
Threat-intelligence hit naming the formbook malware family
Unranked domains with recent registration; OCR text is garbled/incoherent
Domain age information unavailable

Details

Page Title

官方区域合作伙伴    开云体育官网-皇家马德里足球俱乐部

Scan Type

public

Domain Name Analysis

Domain 'www.bqzl36.vip' uses the .vip top-level domain with subdomain 'www'. The registrable portion 'bqzl36' spans 6 characters split between 0 vowels and four consonants; bonus characters include 2 digits. Tokenizing the label suggests three words: bq, zl, 36. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.bqzl36.vip

Page Load Overview

11.93s
Total Load Time
1.1 MB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Text Length:126 chars
Detector Agreement:50%

Website Classification

Primary Category

news media journalism44% confidence
Type: spa
Method: ml+structural

All Detected Categories

news media journalism
44%
adult content
35%
government public service
33%
blog personal website
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1113.70.30.8Azure · CLOUDHong Kong, Hong Kong
AS8075Microsoft Corporation
7154.220.10.112Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
743.243.240.205Hong Kong
AS153494XRUI TECHNOLOGY LIMITED
743.251.114.42Australia
AS132825MYTEK TRADING PTY LTD
714.0.58.130Cdnetworks · CDNBangkok, Bangkok, Thailand
AS54994Meteverse Limited.
395--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12DC23C334909B8770C363C9AE5E26A4E1808D21AD56346C8F2EDF6EAD6DFF095C0F494

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:dEhxQCp8MZTMqtah6mpYZxMU76gGBtS6x9flMjURZsVuSbxfcRBx2OcRBq3hcROE:dEhxQCp8MZThmqdOTBtSk99MjFVuA+2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26607:REKBEkgpgyA2mUAIBRRgWPABYxExJIWiJxmgCJVo5HHqgAALAB5boIwKfKiYCxRwAGoEpETFiIicCqQkVAbAbFKBAAso4RBA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff1818181000
Perceptual Hash:cc8cb306369a9de6
Difference Hash:e0f0b2b2b2b2b0e0
Wavelet Hash:ffffff1818181800
Color Hash:#cc6ce0

Other Hashes

Crop Resistant:e0f0b2b2b2b2b0e0

Scan History

Scan history not available

Unable to load historical scan data