Security Scan Report: bitwarden.criteois.com

Redirected to: https://vault.bitwarden.eu/#/login

Submitted: Mar 25, 2026, 5:32:19 PMCompleted: Mar 25, 2026, 5:33:35 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 2 countries across 2 domains to perform 19 HTTP transactions. The main domain is vault.bitwarden.eu.

Submitted URL: https://bitwarden.criteois.com

Effective URL: https://vault.bitwarden.eu/#/loginRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating Bitwarden login; captures credentials before forwarding to the real vault site.

Risk Factors
Brand impersonation (Bitwarden login on unrelated domain)
Cross‑origin credential form (password+email sent to another domain)
Critical JavaScript obfuscation indicating attempt to hide behavior
Domain age information unavailable

Details

Page Title

Bitwarden Web vault

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(45%)

Domain Information

The domain 'bitwarden.criteois.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'bitwarden'. The core label 'criteois' covers 8 characters split between 4 vowels and 4 consonants. Word splitting yields 3 words: cri, teo, is. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bitwarden.criteois.com

Page Load Overview

2.85s
Total Load Time
17
HTTP Requests
2
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:336 chars
Detector Agreement:50%

Website Classification

Primary Category

cryptocurrency blockchain45% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
45%
technology software
40%
corporate business
32%
government public service
31%
finance banking
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9146.75.121.91Frankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
823.102.12.43Dublin, Leinster, Ireland
AS8075Microsoft Corporation
172--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AA43E9F45B2862FD0CC38BAABF387553B30E91BAFA6D5CC0F25D82552AC3952D617940

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:DjnMUcIibicIibiQIibiqApAFIibicIibiFIibiqApCMi5xoJbGad8nf1ivGVIdX:DjMUNAJb988VU4fB11

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:55957:IgZFsSBCAMHCcBEupQKMVACWEYUAhnrSC0m9ESnH8MEOSAQYQyBAHICOR0kKjgiARAIACQSCQGeEikJABAGipeUiWEAFGMkC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fe7ffe7e7e77e24
Perceptual Hash:a3a38dcd2335998d
Difference Hash:880c084d4c08c8c8
Wavelet Hash:43c3e3e3e4e43c24
Color Hash:#53aca9

Other Hashes

Crop Resistant:880c084d4c08c8c8

Scan History

Scan history not available

Unable to load historical scan data