Security Scan Report: online.no

Redirected to:
https://www.telenor.no/online/
Site favicon
Submitted: May 7, 2026, 8:15:31 PMCompleted: May 7, 2026, 8:17:08 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 6 domains to perform 203 HTTP transactions. The main domain is telenor.no and was registered NaN years ago.

Submitted URL: https://online.no

Effective URL: https://www.telenor.no/online/Redirected

The Cisco Umbrella rank of the primary domain is #257,037 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 82%

7
Risk Score

Site shows strong malicious network activity (C2 beacon, data exfiltration) despite no phishing forms; treat as high‑risk malware distribution and avoid.

Risk Factors
Critical IDS alerts (malware C2 and data exfiltration)
Low Cisco Umbrella ranking for a site claiming a major brand
Brand mismatch between initial domain (online.no) and claimed brand (Telenor)
Multiple redirects increasing suspicion
Domain age information unavailable

Details

Page Title

Online – E-post og nettmagasin fra Telenor

Scan Type

public

Language

🇳🇴

Norwegian

(80% confidence)

Category

cryptocurrency blockchain

(76%)

Domain Information

The domain 'online.no' uses the Norwegian country-code top-level domain (.no). The core label 'online' covers 6 characters holding 3 vowels versus three consonants. Word splitting yields 1 word: online. The median word length lands at 6 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://online.no

Page Load Overview

5.76s
Total Load Time
189
HTTP Requests
5
Domains
2.1 MB
Total Size

Language Analysis

Primary Language

🇳🇴Norwegian
Code: no
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:no
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:no
Text Length:3,161 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain76% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
76%
adult content
74%
technology software
67%
phishing scam
63%
blog personal website
43%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
63150.171.109.100United States
AS8075Microsoft Corporation
63143.204.181.43United States
AS16509Amazon.com, Inc.
6320.100.134.111Oslo, Oslo County, Norway
AS8075Microsoft Corporation
1893--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T120542B21BA0C1021797787BA74F1BE4A7561FB03CA0E89FD7AA285284DD71F73539B48

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:2xvAlkRwFCUaCPf+wI5L4fTmrsQiyE9XO1926dpBYY4DgOQlL1:2xbrsQiyE9XO1926dpBYY4DgOQh1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:298570:iqAFYCcQwJyBAmsUwMLDSCksDURSHIGAKRNggBBawBQZAYBfEgkgZEABFlBARBUBcgkA6mcEBhVICkBKAQA7IwVGIJCVh5BT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff00000000ffffff
Perceptual Hash:e842bd933992ecc3
Difference Hash:23e3e5cdd7030033
Wavelet Hash:ff00000000ffffff
Color Hash:#e06cac

Scan History

Scan history not available

Unable to load historical scan data