Security Scan Report: tools.ip2location.com

Redirected to: https://www.ip2location.com/free/widgets

Submitted: Mar 23, 2026, 2:50:59 AMCompleted: Mar 23, 2026, 2:52:23 AMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 2 countries across 10 domains to perform 118 HTTP transactions. The main domain is ip2location.com and was registered NaN years ago.

Submitted URL: https://tools.ip2location.com

Effective URL: https://www.ip2location.com/free/widgetsRedirected

The Cisco Umbrella rank of the primary domain is #170,073 of the top 1 million websites

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Site contains multiple Indicators of Compromise, hidden password field and credential‑harvesting forms – confirmed phishing scam.

Risk Factors
Hidden password field
Cross‑origin credential form submission
Multiple primary domain Indicators of Compromise matches
Network IDS alerts (medium severity)
High JavaScript obfuscation
Domain age information unavailable

Details

Page Title

Free Multilingual Geolocation Widgets | IP2Location

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(35%)

Domain Information

Within the commercial generic top-level domain (.com), 'tools.ip2location.com' is registered with subdomain 'tools'. Its registrable label 'ip2location' stretches across 11 characters split between five vowels and 5 consonants; bonus characters include one digit. Tokenizing the label suggests 3 words: ip, 2, location. Average segment length settles at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tools.ip2location.com

Page Load Overview

2.81s
Total Load Time
127
HTTP Requests
13
Domains
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:6,447 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate35% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate
35%
technology software
33%
e-commerce shopping
31%

Detected Features

Login Form
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1952.222.236.94United States
AS16509Amazon.com, Inc.
12142.251.127.97United States
AS15169Google LLC
12216.58.206.66United States
AS15169Google LLC
12104.18.95.41United States
AS13335Cloudflare, Inc.
12142.250.186.67United States
AS15169Google LLC
12172.217.16.202United States
AS15169Google LLC
12185.111.111.157Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
12104.17.24.14United States
AS13335Cloudflare, Inc.
12172.67.71.137United States
AS13335Cloudflare, Inc.
12104.26.3.214United States
AS13335Cloudflare, Inc.
12710--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11563C863A1CC2C2723B355C6FC90735870970A3ED5508853FA7B4529B6D9D6A3A2F83B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:DFwaMcYdYIYDY0YZYLYhYEYQYAY6Y8YgYHYcYmYeYtYZYqY8YP0To/B423+eAYdy:RM30G07fy7Juv3lPMt3N+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:73152:gCAOEBA1wswNGhg1DYKgA0KQSUyAOhEkKVFiIcSAAA+gRAwCSghjAoFSjYMQGICLyEgRXIAg6AGzDCAkaqTAHiQwai6EQFeE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffefff81c1f7ffef
Perceptual Hash:e39e94616b9e9461
Difference Hash:295e600b0b060d0b
Wavelet Hash:9c83a781c1e3e7e1
Color Hash:#53ac63

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data