Security Scan Report: irexons.cloud.com

Submitted: Dec 21, 2025, 8:52:42 PMCompleted: Dec 21, 2025, 8:56:11 PMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 5 domains to perform 32 HTTP transactions. The main domain is irexons.cloud.com and was registered NaN years ago.

Submitted URL: https://irexons.cloud.com

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

Impersonates ONS on unrelated domain; high risk phishing.

Risk Factors
Brand impersonation of Office for National Statistics on an unrelated domain
Static credential fields without a proper form, suggesting a phishing lure
Domain age information unavailable

Details

Page Title

Citrix Workspace

Scan Type

public

Language

🇻🇳

VI

(50% confidence)

Category

healthcare medical

(70%)

Domain Information

Domain 'irexons.cloud.com' uses the commercial generic top-level domain (.com), featuring subdomain 'irexons'. The second-level label 'cloud' is 5 characters long holding two vowels versus 3 consonants. It segments into one word: cloud. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://irexons.cloud.com

Page Load Overview

206.92s
Total Load Time
32
HTTP Requests
5
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇻🇳Vietnamese
Code: vi
Confidence:50%
Script:Unknown
Direction:ltr

Detection Details

Language Code:vi
Detection Confidence:50%
Script Type:Unknown
Text Length:6,542 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical70% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
70%
documentation technical
55%
education learning
54%
adult content
52%
technology software
50%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
813.35.58.73United States
AS16509AMAZON-02
313.107.213.44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
313.107.246.44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
335.186.247.156United States
AS396982GOOGLE-CLOUD-PLATFORM
320.223.37.112Dublin, Leinster, Ireland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
313.35.58.15United States
AS16509AMAZON-02
313.35.58.100United States
AS16509AMAZON-02
334.111.138.51Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
313.35.58.51United States
AS16509AMAZON-02
329--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T150836BA309843836AA170137F9CB934F530BA1272D938849E0FEAD56C7C9D4D1BB176E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:G49lmBaYq/hORll6LsWdFr+g2ornmlRFuN6WMSZbf0ejgKyVLosUzFp:Ge8ysWGv8x0LosUzFp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:85447:ELQAAkgkoZRQCFTEjgkgEXKPgCplFPQICkJQChk8QIGFQCFEEkgUwbBA8oyQKOJAKuV1ZQQhBAgoASyeCEBJ4BDImVwTSDNo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00c7ffffffff81ff
Perceptual Hash:fdd3286d823dc22c
Difference Hash:1f1ee0b8e8803332
Wavelet Hash:00007e7e7e7e007f
Color Hash:#2d2fd2

Scan History

Scan history not available

Unable to load historical scan data