Security Scan Report: pay-uiys.net

Redirected to: https://www.lemonde.fr/

Submitted: Nov 19, 2025, 10:51:16 PMCompleted: Nov 19, 2025, 10:53:01 PMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 3 countries across 7 domains to perform 104 HTTP transactions. The main domain is lemonde.fr.

Submitted URL: https://pay-uiys.net/as.php

Effective URL: https://www.lemonde.fr/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

pay-uiys.net impersonates Le Monde and redirects to the real site; classified as confirmed phishing scam.

Risk Factors
Brand impersonation on a newly registered, unranked domain
Untrusted initial domain (pay-uiys.net) used to lure users to a reputable site
Lack of legitimate purpose for the pay-uiys.net domain
Domain age information unavailable

Details

Page Title

pay-uiys.net

Scan Type

public

Language

🇫🇷

French

(80% confidence)

Category

news media journalism

(77%)

Domain Information

The domain name 'pay-uiys.net' uses the network infrastructure generic top-level domain (.net) and has no subdomain. Count 8 characters in 'pay-uiys' split between three vowels and 4 consonants, plus 1 hyphen. Breaking it apart gives three words: pay, ui, ys. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pay-uiys.net/as.php

Page Load Overview

1.68s
Total Load Time
104
HTTP Requests
7
Domains
1.8 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:fr
Text Length:64,334 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism77% confidence
Type: static
Method: ml+structural

All Detected Categories

news media journalism
77%
government public service
65%
corporate business
60%
corporate
25%
news/blog
20%

Detected Features

Articles
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
95146.75.122.217Frankfurt am Main, Hesse, Germany
AS54113FASTLY
16184.30.22.30Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
818.245.86.4United States
AS16509AMAZON-02
8172.67.212.172United States
AS13335CLOUDFLARENET
82606:4700:3034::ac43:d4acUnited States
AS13335CLOUDFLARENET
818.245.86.69United States
AS16509AMAZON-02
82606:4700:3037::6815:25c1United States
AS13335CLOUDFLARENET
818.245.86.111United States
AS16509AMAZON-02
2104.21.37.193United States
AS13335CLOUDFLARENET
191.215.85.212Russia
AS200593Prospero Ooo
10412--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AC048F77329A063986454499E057430D9F20B143B50ACDBCBABCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:/fQho9PKBb9JsE9RHCbZgRjFtSBaw9QWgceIszA2bMy8Oldc:AhoC9J395CbZgLtSL3gcrs82eAi

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:183572:MQO3dAQNQBFgJ/AwAAEzQxASAkoJeIijkJAFuUGAuEIWhLAWAZxBUsgaAxYQBMAiA5g38gAmAi4G6M0IGKQCxA7pOQISpoMi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3c7ffffffff
Perceptual Hash:b3318ccccc673333
Difference Hash:00180c1400000000
Wavelet Hash:3c1c000c0f0f0f0f
Color Hash:#93721f

Other Hashes

Crop Resistant:00180c1400000000

Scan History

Scan history not available

Unable to load historical scan data