Security Scan Report: treasurydirect.gov

Submitted: Dec 15, 2025, 7:13:16 PMCompleted: Dec 15, 2025, 7:14:48 PMpubliccompleted
Loading additional data...

Summary

This website contacted 50 IPs in 2 countries across 12 domains to perform 45 HTTP transactions. The main domain is treasurydirect.gov and was registered NaN years ago.

Submitted URL: https://treasurydirect.gov/

The Cisco Umbrella rank of the primary domain is #153,484 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 88%

7
Risk Score

High‑risk phishing page impersonating Google on TreasuryDirect domain.

Risk Factors
Brand impersonation on non‑official domain
Low domain ranking for brand claim (rank >100k)
Domain age information unavailable

Details

Page Title

Home — TreasuryDirect

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government public service

(51%)

Domain Information

The domain name 'treasurydirect.gov' uses the United States government-restricted top-level domain (.gov). Its registrable label 'treasurydirect' stretches across 14 characters with five vowels and 9 consonants. Breaking it apart gives two words: treasury, direct. The median word length lands at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://treasurydirect.gov/

Page Load Overview

45.16s
Total Load Time
45
HTTP Requests
12
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:6,446 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service51% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
51%
government
48%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
45164.95.95.225Ashburn, Virginia, United States
AS13506US-DEPARTMENT-OF-THE-TREASURY
03.174.46.54United States
AS16509AMAZON-02
0142.251.141.100United States
AS15169GOOGLE
0216.239.34.36United States
AS15169GOOGLE
0142.250.185.72United States
AS15169GOOGLE
0208.95.152.110United States
AS12200RACKSPACE
0142.251.141.99United States
AS15169GOOGLE
0216.239.32.36United States
AS15169GOOGLE
0216.58.206.42United States
AS15169GOOGLE
0142.250.186.131United States
AS15169GOOGLE
4550--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13F23C712A8F0343B42D392E676F25B0DBE91A003F50A9C2876BD47C96FE5F468D17A4D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:bhI9KJpagxmNyCaydKDvjzynyeB8VwbX0CQXGkBJUR7x55ij:aYJxvjzynyeB8VwbX0NXPBw7x55ij

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:49571:hMITUkE0RAM8FEHBkAAKAQJgwwqURICXEyAEKAJGUgMVFBdQJTAABAEWiDIJUwbcKYylDhiVQBmEN6yGTQgEOKyHkmAQVAIE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff9f040404ffffff
Perceptual Hash:9636e9c903f93c16
Difference Hash:633c3c4ccc312a23
Wavelet Hash:2a06060004ffffff
Color Hash:#e0966c

Scan History

Scan history not available

Unable to load historical scan data