Security Scan Report: whats-xtl.vip

Submitted: Oct 27, 2025, 11:06:08 AMCompleted: Oct 27, 2025, 11:07:24 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is whats-xtl.vip and was registered NaN years ago.

Submitted URL: http://whats-xtl.vip/

AI Security Verdict

High Risk

Confidence: 95%

10
Risk Score

Site shows multiple high‑risk indicators and should be avoided.

Risk Factors
Social Engineering threat detected by Google Safe Browsing
Circular redirect indicating possible URL manipulation
Brand‑new domain (<7 days) with no reputation
Unranked domain in Cisco Umbrella
Domain age information unavailable

Details

Page Title

Sorry, the website has been stopped

Scan Type

public

Language

🇺🇸

English

(52% confidence)

Category

adult content

(27%)

Domain Information

The domain 'whats-xtl.vip' uses the .vip top-level domain without a subdomain. Count 9 characters in 'whats-xtl' split between one vowel and 7 consonants; it also includes 1 hyphen. Tokenizing the label suggests four words: what, s, x, tl. Median word length is 1.5 characters. 'what' most often appears in English. It also appears in Chinese (Pinyin) and Slovenian contexts.

Screenshot

Security scan screenshot of http://whats-xtl.vip/

Page Load Overview

19.20s
Total Load Time
4
HTTP Requests
1
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:52%
Script Type:Latin
Text Length:129 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content27% confidence
Type: static
Method: ml+structural

All Detected Categories

adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
420.2.67.40Hong Kong, Hong Kong
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
41--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19943021803DE40A3CD9968D9426B3F3C842A5873DA1C98BD1F5B6DB4CA0D8A47A7F1E5

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:FHJYDDQHVZHIs91TXESJBjgBSp00yCqJ3Z+IYM3WiesRQiULO0bpD9tcNQEfdomi:lmDD6oeFUycwpk06hWp1b99c7VE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:58253:EUiMaVDSkYS0xkQBgAkJSACzQIEOFMICYgADRgmqEAc4cMJYSg0AOpCEVUQVAwAAYQDCQ8gDQFAQFNNopDOJaYVIypATErIC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7e7e7ffffffff
Perceptual Hash:e6668c99993333c6
Difference Hash:00080c0c00000000
Wavelet Hash:ffe7e7c300000000
Color Hash:#5391ac

Other Hashes

Crop Resistant:00080c0c00000000

Scan History

Scan history not available

Unable to load historical scan data