Security Scan Report: www.icicibankinvoice.de

Redirected to:
https://www.icicibankinvoice.de/login.php
Site favicon
Submitted: Sep 22, 2026, 8:42:30 PMCompleted: Sep 22, 2026, 8:43:09 PMpubliccompleted

This website contacted 3 IPs in 2 countries across 3 domains to perform 18 HTTP transactions. The main domain is icicibankinvoice.de and was registered 18 years ago.

Submitted URL: https://www.icicibankinvoice.de

Effective URL:

https://www.icicibankinvoice.de/login.php
Redirected

AI Security Verdict

Low Risk

Confidence: 58%

3
Risk Score

Long-registered domain (18 yrs) presenting an ICICI Bank Germany 'Easy Bill' employee login. No threat-intel, malware, or exfiltration signals; reads like an internal invoicing portal, though its official affiliation is unverified.

Risk Factors (2)
Domain is unranked / not in Cisco Umbrella top 1M
Credential login form served on a .de domain that is not the bank's official primary domain, so ownership/affiliation cannot be independently verified
Safety Factors (5)
Established 18-year-old registration
Employee ID-based login (internal/business portal rather than consumer phishing)
Brand name matches the domain name (no mismatched typosquat)
No IoC, YARA, IDS, or Safe Browsing hits
No credential exfiltration or cross-origin form posts
Domain age information unavailable

Details

Page Title

EasyBill - Login

Scan Type

public

Domain Name Analysis

Domain 'www.icicibankinvoice.de' uses the German country-code top-level domain (.de); it also runs on subdomain 'www'. The registrable portion 'icicibankinvoice' spans 16 characters with 8 vowels and eight consonants. Tokenizing the label suggests five words: i, cici, bank, in, voice. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.icicibankinvoice.de

Page Load Overview

2.01s
Total Load Time
1015 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:74%
Script:Latin
Direction:ltr

Detection Details

Text Length:309 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking75% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
75%
technology software
71%
documentation technical
38%
government public service
32%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
698.67.186.81Azure · CLOUDFrankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
6142.251.13.95Google · CDNUnited States
AS15169Google LLC
6142.251.110.94Google · CDNUnited States
AS15169Google LLC
183--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B681331474F918675043D4D566117A0A6FE4C203CA1B9A08B6FC1FD46FD6E83CC5366C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:G4qpqpKiJnkJX6eGSgN0rwvV38a5jGSpIOSi3egOCQkbfGfYUVk:P2iBkJX1g0yh8ojrZhONCB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3922:QEAIAEAAXIVICApkIAFoDQglRAQECoBAAAGgECAIwGBACBCQAgGQAAABYAQAEAgAQAACgIACgICggACAAPwAERgEyEAC0gAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f7f7f7939380e00
Perceptual Hash:818036db69976ab7
Difference Hash:dfcdc6d3d3515c66
Wavelet Hash:7f7f7f3939200600
Color Hash:#40931f

Scan History

Scan history not available

Unable to load historical scan data