Security Scan Report: pochta.kwid9.usepay.xyz

Redirected to:
https://bulsis.net/go/2735916?ref=&subid1=
Submitted: May 21, 2026, 7:14:06 PMCompleted: May 21, 2026, 7:15:34 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is bulsis.net and was registered NaN years ago.

Submitted URL: https://pochta.kwid9.usepay.xyz

Effective URL: https://bulsis.net/go/2735916?ref=&subid1=Redirected

AI Security Verdict

Safe Website

Confidence: 82%

0
Risk Score

The site shows no malicious indicators, has a well‑established domain, and lacks credential or payment forms; it is classified as legitimate.

Safety Factors
Long‑standing domain (>2 years)
Absence of credential‑collection forms
No malicious Indicators of Compromise
No malware‑related YARA matches
Low JS obfuscation score indicating standard minification
Domain age information unavailable

Details

Page Title

...

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

Within the open generic top-level domain (.xyz), 'pochta.kwid9.usepay.xyz' is registered with subdomain 'pochta.kwid9'. The registrable portion 'usepay' spans 6 characters containing three vowels alongside 3 consonants. It segments into 2 words: use, pay. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pochta.kwid9.usepay.xyz

Page Load Overview

7.91s
Total Load Time
5
HTTP Requests
2
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:3 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5157.90.33.74Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
51--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D3E1E8D135D038602392A1E77D33B6ADF566DDE2670A5C44F56C78B4FF06E04842316C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:+25DIQJt0YcTwf1qgnds3AsDdZCzR72Jw6DG7xa5RpDALts2Epx1xRUdSJvL:xDIQJBj17GQsDdZCzpb6bj2u2Epvr9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6871:CAaB7AQaQMxiY8EmuBJAAQIaARSGEAAIqAsgMElMwTgAiBQQAKkEAFEFRFAYiACgQIgJhSSZERKIIEkPIIiYxZSEEPQlgYIA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c7dfcfffffffff
Perceptual Hash:b83133733138c7c7
Difference Hash:1c1c041410000000
Wavelet Hash:c3c3c3c3f0f0f0f0
Color Hash:#79d2cf

Other Hashes

Crop Resistant:1c1c041410000000

Scan History

Scan history not available

Unable to load historical scan data