Security Scan Report: deref-mail.com

Site favicon
Submitted: Oct 2, 2025, 1:26:11 AMCompleted: Oct 2, 2025, 1:27:07 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 3 countries across 4 domains to perform 15 HTTP transactions. The main domain is deref-mail.com.

Submitted URL: https://deref-mail.com/mail/client/yFeUu-PFAHw/dereferrer/?redirectUrl=https%3A%2F%2Fclick-notification.capitalone.com%2Ff%2Fa%2FAwbYliMxS6doIWejRxpfmQ~~%2FAAAAAQA~%2FRgRoTurFP0R1aAL6UMGLeR4HQt7Aq8nreT38AjsPbzR2OC9jP3BPV69KfsPcw7G7CjdmvWVqXHSj9Xdtxb827uvUJEsQ2jPmYx2aZBE6er5xJVi5uZXRYBAAAAAA~&lm

The Cisco Umbrella rank of the primary domain is #590,623 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

The site is a high‑risk phishing redirect using brand impersonation; do not click or provide any data.

Risk Factors
Unranked, low‑reputation domain
Brand impersonation via page title
Potentially newly registered domain
Redirect to external Capital One link
Used as a dereferrer in phishing‑style URLs
Domain age information unavailable

Details

Page Title

mail.com - Error

Scan Type

public

Language

🇺🇸

English

(58% confidence)

Category

news media journalism

(34%)

Screenshot

Security scan screenshot of https://deref-mail.com/mail/client/yFeUu-PFAHw/dereferrer/?redirectUrl=https%3A%2F%2Fclick-notification.capitalone.com%2Ff%2Fa%2FAwbYliMxS6doIWejRxpfmQ~~%2FAAAAAQA~%2FRgRoTurFP0R1aAL6UMGLeR4HQt7Aq8nreT38AjsPbzR2OC9jP3BPV69KfsPcw7G7CjdmvWVqXHSj9Xdtxb827uvUJEsQ2jPmYx2aZBE6er5xJVi5uZXRYBAAAAAA~&lm

Page Load Overview

23.25s
Total Load Time
15
HTTP Requests
4
Domains
136 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:58%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:153 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism34% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

news media journalism
34%
documentation technical
32%
social media network
32%
technology software
31%
entertainment media
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
523.32.96.185Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
574.208.232.57United States
AS8560IONOS SE
52.19.216.191Prague, Prague, Czech Republic
AS16625AKAMAI-AS
153--

Detected Technologies1

JQueryv1.12.4
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T157B172274D05883715A242E4F972EA1AD0D19628FB13ECC9DBF097CE63E4FC6990A715

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:cShXkY+HLYSMl6pfsOxbmJfQT2SbucmAGin:cShXr+HUX6pf1xRbucjx

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5148:HCAISAETESAQgAiIIoCGAYFJARIQCgQAkEAZByEIXIASh1FQQCCAEASEoCRZQQCYAGCCEiAEEDgACJAACiJAIEAREEEADAAC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:efc6fefefefefefe
Perceptual Hash:f533b3a08ccccccc
Difference Hash:0e5e220202020202
Wavelet Hash:fee60010f0f0f0f0
Color Hash:#c587b5

Other Hashes

Crop Resistant:0e5e220202020202

Scan History

Scan history not available

Unable to load historical scan data