Security Scan Report: klarna-refund.app

Submitted: Sep 23, 2026, 3:10:01 PMCompleted: Sep 23, 2026, 3:10:54 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Domain name mimics Klarna with a refund lure, but the page currently serves only a Cloudflare 522 timeout error with no content or forms. Suspicious branding on an unranked domain; avoid entering any data.

Risk Factors (3)
Deceptive hostname using a third-party payment brand (Klarna) with a refund bait term on a non-official domain
Origin server is unreachable — site content could not be inspected, leaving intent unverified
No reputation in Cisco Umbrella and no legitimacy signals beyond 302-day domain age
Safety Factors (4)
Page content is a generic Cloudflare error, not a credential or payment page
No credential, login, or payment forms present (0 forms, 0 password fields)
No Indicators of Compromise, no JavaScript malware patterns, and no network IDS alerts
No cross-origin credential exfiltration detected
Domain age information unavailable

Details

Page Title

klarna-refund.app | 522: Connection timed out

Scan Type

public

Domain Name Analysis

The domain 'klarna-refund.app' uses the application-focused generic top-level domain (.app). Count 13 characters in 'klarna-refund' split between 4 vowels and 8 consonants, plus one hyphen. Segmentation suggests 3 words: kl, arna, refund. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://klarna-refund.app

Page Load Overview

19.80s
Total Load Time
23 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:944 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical61% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
61%
technology software
59%
government public service
43%
cryptocurrency blockchain
38%
news media journalism
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.21.80.116Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.180.130Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T169E15471B1F5527600A381923695FB6A75E0C617CBFF449473DDC2732F9EE81A903294

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:leDa/D2KUldG4Fh8/G4FUGfZ424Fe+skKm/jotQmHB+dWShmnRC3/qaQxx:lea/CfeqIVyjoWQ+DhmnM3Nex

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6974:eCAKkAygKQCCdgsa8ABBAikGYBAhgkXAccRCICIBBIICNCSAAgSSJRhaBgMM6IABVAgIhACUoGBCHCQYQtIAJK2UFKAJgCBY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7cf0000d7d7f3ff
Perceptual Hash:f439b3b493653065
Difference Hash:1c3e8e8a2c260606
Wavelet Hash:c70e0000d6c7f3ff
Color Hash:#53ac7d

Other Hashes

Crop Resistant:1c3e8e8a2c260606

Scan History

Scan history not available

Unable to load historical scan data