Security Scan Report: ntvip-173.pages.dev

Site favicon
Submitted: Jan 1, 2026, 7:25:22 AMCompleted: Jan 1, 2026, 7:26:34 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 6 domains to perform 37 HTTP transactions. The main domain is ntvip-173.pages.dev and was registered NaN years ago.

Submitted URL: https://ntvip-173.pages.dev/global-index

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing site due to malicious pages.dev domain and Apple brand impersonation.

Risk Factors
Malicious Indicators of Compromise match on primary domain
Brand impersonation/typosquatting on an unranked domain
Use of a pages.dev subdomain known for malicious activity
Domain age information unavailable

Details

Page Title

Speedtest Global Index – Internet Speed around the world – Speedtest Global Index

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(41%)

Domain Information

You're looking at domain 'ntvip-173.pages.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'ntvip-173'. Count 5 characters in 'pages' containing 2 vowels alongside 3 consonants. Splitting it apart reveals 1 word: pages. The median word length lands at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ntvip-173.pages.dev/global-index

Page Load Overview

7.53s
Total Load Time
29
HTTP Requests
7
Domains
3.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:16,071 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical41% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
523.36.162.25Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
3172.66.46.230United States
AS13335CLOUDFLARENET
313.32.121.61Germany
3172.66.45.26United States
AS13335CLOUDFLARENET
313.32.121.112New York, New York, United States
AS16509AMAZON-02
3104.16.5.65GermanyUnknown
323.36.162.6GermanyUnknown
3104.18.86.42United States
AS13335CLOUDFLARENET
3146.75.122.219Frankfurt am Main, Hesse, Germany
AS54113FASTLY
299--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D9654224A5F0663BD43752C5A2E2BF8318D56283C254094177FC8AA66F9ACFFB10F64D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:MLN7kz0Hvn7ELaxvnOlE1VW3HOrinngfpHcPVn/wqSYZYke5nVubPq:MLNgvyWWxDzY5Pq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1449514:SJEhMCAGgZYCxQgMQSkEhjA/IMBsADhCGlQodPGIFQCPABNPCQRcAEATEhNCAQkEIGQgDEEMBLAAA2JABB4tFQgRGIDSDQwh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000fffffbfbfffb
Perceptual Hash:e916124969b6e9bc
Difference Hash:c5c5000c23232623
Wavelet Hash:0000effff1d9c3c1
Color Hash:#ac5384

Scan History

Scan history not available

Unable to load historical scan data