Security Scan Report: chc.ssffaa4.xyz

Redirected to:
https://2026-09-18.urldance.com/english?ssffaa4.xyz
Site favicon
Submitted: Sep 18, 2026, 2:47:33 AMCompleted: Sep 18, 2026, 2:49:29 AMpubliccompleted

This website contacted 7 IPs in 4 countries across 6 domains to perform 8 HTTP transactions. The main domain is 2026-09-18.urldance.com and was registered 26 years ago.

Submitted URL: https://chc.ssffaa4.xyz

Effective URL:

https://2026-09-18.urldance.com/english?ssffaa4.xyz
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Domain family carries multi-feed Vidar infostealer IoCs and the page is a password-only 'verify to unlock' gate redirecting to an unrelated domain — credential/malware risk, avoid.

Risk Factors (5)
Content-malware threat-intel match: Vidar stealer on the site's own registrable domain (2 corroborating feeds)
Password-only form ('Enter password to access resource links') with no username field — credential capture pattern
Entry domain redirects to an unrelated destination domain hosting the credential prompt
Dynamic code execution via eval() and Function() constructor
Urgency phrasing 'High traffic, please verify password' pressuring credential entry
Domain age information unavailable

Details

Page Title

Resource Library - Premium Content, Secure Access

Scan Type

public

Domain Name Analysis

You're looking at domain 'chc.ssffaa4.xyz' on the open generic top-level domain (.xyz) with subdomain 'chc'. The registrable portion 'ssffaa4' spans 7 characters holding two vowels versus 4 consonants, plus 1 digit. Breaking it apart gives five words: s, s, ffa, a, 4. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://chc.ssffaa4.xyz

Page Load Overview

85.32s
Total Load Time
44 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:x-default
Text Length:261 chars
Detector Agreement:100%
Language mismatch: Declared as x-default but detected as en

Website Classification

Primary Category

adult content46% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
46%
government public service
35%
news media journalism
34%
cryptocurrency blockchain
31%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
254.215.31.113Aws · CLOUDSan Jose, California, United States
AS16509Amazon.com, Inc.
1156.225.108.42Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1156.225.108.43Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1156.225.108.41Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1183.60.255.95China
AS4134Chinanet
1111.45.11.83China
AS9808China Mobile Communications Group Co., Ltd.
143.159.107.113Singapore
87--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T154914E3045F8653F948281C86A39E76EBAD1D84BDA5F4100B6FC6BA44F87EC2DC37258

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:CkbEpKmvdTu8xR8xR8xR8xsq5qXCEL5CdJrAYjlMJHbSdR8n5Tn9sz5mX3C4Rl9K:CkMKsFx5tFTBSLGEmbRzFd102u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4441:QKGQKAATLAEkIBgIARggASAMAgEIACAOACgBgAoRBEgAACISAOAADTMAGIKwQCwBgAAAgEpjIoBCIREANjgiyEAQEAIwUALA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:897173ce66899933
Difference Hash:0c32b3b3b3b3b3cf
Wavelet Hash:c4d8d9191d1f3f03
Color Hash:#c9e06c

Scan History

Scan history not available

Unable to load historical scan data