Security Scan Report: check-0mhs9f3bj.devwatchalerts.cyou

Site favicon
Submitted: Sep 14, 2026, 4:23:53 AMCompleted: Sep 14, 2026, 4:24:12 AMpubliccompleted

This website contacted 5 IPs in 1 country across 5 domains to perform 16 HTTP transactions. The main domain is check-0mhs9f3bj.devwatchalerts.cyou and was registered 3 years 5 months ago.

Submitted URL: https://check-0mhs9f3bj.devwatchalerts.cyou/?address=poNSfquKq512ApeYjVghwViSun4x1MhCqHVH2Paq4jN

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Four-day-old .cyou domain flagged as phishing hosting a fake Solana rug-checker that pushes wallet-connect prompts — likely a wallet drainer. Do not connect a wallet.

Risk Factors (4)
4-day-old domain on an abused .cyou TLD
Domain reported as phishing (content-malware Indicator of Compromise)
Repeated wallet-connect prompts on a brand-new unknown domain — wallet-drainer pattern
Zero verifiable identity/company info behind a tool claiming to scan 2.4M wallets
Domain age information unavailable

Details

Page Title

DEVWATCH — Analysis: poNSfquK...q4jN

Scan Type

public

Domain Name Analysis

You're looking at domain 'check-0mhs9f3bj.devwatchalerts.cyou' on the .cyou top-level domain, featuring subdomain 'check-0mhs9f3bj'. Its registrable label 'devwatchalerts' stretches across 14 characters split between 4 vowels and 10 consonants. Word splitting yields three words: dev, watch, alerts. Median word length is five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://check-0mhs9f3bj.devwatchalerts.cyou/?address=poNSfquKq512ApeYjVghwViSun4x1MhCqHVH2Paq4jN

Page Load Overview

1.43s
Total Load Time
425 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,062 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.110.95Google · CDNUnited States
AS15169Google LLC
3142.250.154.94Google · CDNUnited States
AS15169Google LLC
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.36.169Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
165--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T158E2E6B2A214603AF437D4C2B6C467EF70A49407EC2746ACEAD4965DC6CBEF35A30758

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:EZMG0T0DEVuRIhnATIeee24ollu7pAVJnoLvwIAlq8e:m3kXVuRfeq8e

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33365:COENpRAEUkhFAqkih0CKIggrjCiCg3AAAnaQZC2ZGuDJMCSlYYgJCBgDPQFDgCIGJIARIoAAAyCAMxohaISQCARCRQiBBEGQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:8000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#862d3e

Other Hashes

Crop Resistant:8000000000000000

Scan History

Scan history not available

Unable to load historical scan data