Security Scan Report: nellia.online

Site favicon
Submitted: Dec 28, 2025, 1:21:28 AMCompleted: Dec 28, 2025, 1:21:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 2 countries across 4 domains to perform 39 HTTP transactions. The main domain is nellia.online and was registered NaN years ago.

Submitted URL: https://nellia.online/bank/signup/verify-registration.php

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

New, unranked domain impersonating a bank and collecting passwords – confirmed phishing scam.

Risk Factors
Newly registered domain (<7 days) used for credential collection
Credential harvesting form with multiple password fields
Brand impersonation of a bank on an untrusted domain
Unranked domain with low reputation
Absence of any legitimate brand verification (final URL not official bank domain)
Domain age information unavailable

Details

Page Title

Registration - NELLIA BANK

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(53%)

Domain Information

Within the modern generic top-level domain (.online), 'nellia.online' is registered with no subdomain. The second-level label 'nellia' is 6 characters long split between 3 vowels and 3 consonants. It segments into three words: nell, i, a. The median word length lands at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nellia.online/bank/signup/verify-registration.php

Page Load Overview

9.29s
Total Load Time
39
HTTP Requests
0
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,503 chars
Detector Agreement:75%

Website Classification

Primary Category

finance banking53% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
53%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
33137.74.4.139Poland
AS16276OVH SAS
2104.26.13.42United States
AS13335CLOUDFLARENET
1152.3.138.25United States
AS13371DUKE-INTERCHANGE
1142.250.184.202UnknownUnknown
04--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14843C8629CD0141BE0274EAD9EE4EA0C29E4C203ED370D4DB2ACD6948FD7E8F595735A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:1Cs7PUPFZv8KZe2T5Dw8YlY9PTMYeIgQmZ4isA1wkerUPpUj1yEt:1CH8g50qA1wkerKA1yEt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:60540:QFCCno0kdQWMoQRAg0QIhlcQoUbALZ0BIAes+RBgZsDQJwQICEQlUKKDggDAyQtiaSAAU0CnfoCsABEbTXoKCAMJAQw5AEwv

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data