Security Scan Report: mw.secure.vpr.lol

Redirected to: https://mw.secure.vpr.lol/

Submitted: Mar 14, 2026, 7:32:45 PMCompleted: Mar 14, 2026, 7:34:22 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 1 country across 7 domains to perform 40 HTTP transactions. The main domain is mw.secure.vpr.lol and was registered NaN years ago.

Submitted URL: http://mw.secure.vpr.lol/

Effective URL: https://mw.secure.vpr.lol/Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Site impersonates IXL brand on a new, unranked domain without collecting credentials; treat as high‑risk brand impersonation.

Risk Factors
Brand impersonation via meta tags
New domain (<180 days old)
Unranked domain (not in top 1M)
JavaScript obfuscator usage detected by Suricata
Domain age information unavailable

Details

Page Title

VAPOR v4

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

education learning

(98%)

Domain Information

Domain 'mw.secure.vpr.lol' uses the .lol top-level domain; it also runs on subdomain 'mw.secure'. Count 3 characters in 'vpr' holding zero vowels versus three consonants. Tokenizing the label suggests two words: v, pr. Median word length is 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://mw.secure.vpr.lol/

Page Load Overview

0.19s
Total Load Time
3
HTTP Requests
1
Domains
8 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:39,982 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning98% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

education learning
98%
adult content
62%
government public service
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.16.175.226Germany
0172.217.16.200Germany
0172.240.127.234Germany
0159.195.59.55Nuremberg, Bavaria, Germany
AS197540netcup GmbH
05.188.124.24Germany
0142.251.143.99Germany
0216.58.206.74Germany
37--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18F431E2B79F12A660AD7505B21234A80DFB9850FBA111C80F9FE43643F1695E93E377B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:2MUMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMNMc:G

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:59913:CAOBK4KFXIFoyKMJ4FoEAkBA0CQiAEGgCAtOqCQFIiEY4SqXLEEFhGAP8SgdDOkAwgZQGE4ZQBQAhlZMC2kGAaBHEcA1gGLQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000018181818000f
Perceptual Hash:8c6e3359cc4cdd64
Difference Hash:330f333332321c70
Wavelet Hash:998119191b1f1f3f
Color Hash:#87c5bc

Other Hashes

Crop Resistant:330f333332321c70

Scan History

Scan history not available

Unable to load historical scan data