Security Scan Report: netextender.pl

Site favicon
Submitted: Sep 17, 2026, 3:47:36 AMCompleted: Sep 17, 2026, 3:48:18 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Unofficial NetExtender VPN download/fan page on an unranked 145-day-old domain, tagged by a single unverified source as Bumblebee malware. No forms or active malicious JS seen, but do not download software from it.

Risk Factors (3)
Malware-family Indicator of Compromise naming this exact primary domain (single-source, unverified)
Third-party download page for a legitimate vendor's security client hosted on an unrelated, unranked domain
Content mimics the vendor's download/informational structure without authorization, inviting users to fetch software from a non-official source
Domain age information unavailable

Details

Page Title

Download SonicWall NetExtender

Scan Type

public

Domain Name Analysis

You're looking at domain 'netextender.pl' on the Polish country-code top-level domain (.pl) and has no subdomain. The second-level label 'netextender' is 11 characters long split between four vowels and 7 consonants. It segments into two words: net, extender. Average segment length settles at 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://netextender.pl

Page Load Overview

15.23s
Total Load Time
889 KB
Total Size

Language Analysis

Primary Language

🇵🇱Polish
Code: pl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pl
Text Length:9,176 chars
Detector Agreement:75%

Website Classification

Primary Category

education learning99% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

education learning
99%
technology software
94%
corporate business
82%
documentation technical
76%
download file sharing
70%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1023.94.80.228Buffalo, New York, United States
AS36352HostPapa
10142.250.154.95Google · CDNUnited States
AS15169Google LLC
10142.251.110.94Google · CDNUnited States
AS15169Google LLC
303--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11C41C12F4480EF56221CEB54D6CA39CD843B420BA31C69E364DB095B78F9FD0847F16A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:hgHNXjaQMZUNAeHNXjaQMkqUXNJ+S3LHNXjaQMUS3DYnd:KteGtecNTLtePcd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2159:EAAIAABABAAAAEAACCAAAEAFAIACAIAAwAAAAAIIAAkAGCAIAAAAAIggIIBAoAABAIAgAA4AACAAUAAAAIAAAACAAABEAASA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0602000000ffff
Perceptual Hash:8611f1db4ecc70f8
Difference Hash:d8dcdee7e1d9b104
Wavelet Hash:ff0707110000ffff
Color Hash:#add279

Scan History

Scan history not available

Unable to load historical scan data