Security Scan Report: ecwid-plans.com

Redirected to: https://ecwid-plans.com/cc.html

Submitted: Jan 23, 2026, 8:58:13 AMCompleted: Jan 23, 2026, 8:59:31 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 1 HTTP transaction. The main domain is ecwid-plans.com and was registered NaN years ago.

Submitted URL: http://ecwid-plans.com/cc.html

Effective URL: https://ecwid-plans.com/cc.htmlRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed scam: payment phishing on a brand‑impersonating, brand‑new domain.

Risk Factors
Brand impersonation on a newly registered domain
Payment collection form on suspicious domain
Domain age < 7 days with credential/payment collection
Domain age information unavailable

Details

Page Title

Account Verification | Ecwid

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

e-commerce shopping

(93%)

Domain Information

Domain 'ecwid-plans.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. The registrable portion 'ecwid-plans' spans 11 characters holding 3 vowels versus 7 consonants; it also includes 1 hyphen. Tokenizing the label suggests 3 words: ecw, id, plans. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://ecwid-plans.com/cc.html

Page Load Overview

1.16s
Total Load Time
6
HTTP Requests
3
Domains
59 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:396 chars
Detector Agreement:75%

Website Classification

Primary Category

e-commerce shopping93% confidence
Type: static
Method: ml+structural

All Detected Categories

e-commerce shopping
93%
finance banking
47%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2129.121.74.9United States
AS31898ORACLE-BMC-31898
2104.26.3.143United States
23.171.211.114United States
63--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DA63C01E21E404BE7C9780F6B5B5BA087D77A183DD2AC1F6FA8E42411FC9A719493748

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:9hncjJh8uPw4ahkCJ3P7y55S4dWQo/KEAGvzfaQeC2:9hnY8unekaPW5zW9PL7at

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70665:fwBkYklQDAFjiAEg+GhtMDySVCAohfoKGKKLjNUnETiWEAKFiAogKAtCYiKIQQQXEACjsChgAvoQ2AQQgBEEBhCCQODwnmJY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffff9fdfdfdff3f3
Perceptual Hash:ec92659833679a6c
Difference Hash:c4c43c14b4b8c6c6
Wavelet Hash:7c7e0e1e565e7030
Color Hash:#9940bf

Other Hashes

Crop Resistant:c4c43c14b4b8c6c6

Scan History

Scan history not available

Unable to load historical scan data