Security Scan Report: check-qcpvdzi.devwatchalerts.cyou

Site favicon
Submitted: Sep 13, 2026, 4:52:00 AMCompleted: Sep 13, 2026, 4:53:01 AMpubliccompleted

This website contacted 6 IPs in 1 country across 6 domains to perform 19 HTTP transactions. The main domain is check-qcpvdzi.devwatchalerts.cyou and was registered 3 years ago.

Submitted URL: https://check-qcpvdzi.devwatchalerts.cyou/?address=BUF5RkVevNXn4VpPYPToeXm75WE1qFAurLfQwSYGpump

AI Security Verdict

High Risk

Confidence: 70%

8
Risk Score

3-day-old .cyou domain flagged for phishing, unranked, and hosting a Solana 'wallet analysis' tool that pushes a Connect Wallet prompt — high-risk crypto-drainer profile. Avoid connecting any wallet.

Risk Factors
Domain age 3 days old — extreme phishing/drainer risk
Phishing threat-intelligence match on the primary domain (single-source, unverified)
No domain reputation — unranked in Cisco Umbrella
Crypto wallet-connect prompt on a newly registered, unranked domain
Potentially bad traffic indicated by IDS (.cc TLD DNS query)
Domain age information unavailable

Details

Page Title

DEVWATCH — Analysis: BUF5RkVe...pump

Scan Type

public

Domain Name Analysis

The domain 'check-qcpvdzi.devwatchalerts.cyou' uses the .cyou top-level domain with subdomain 'check-qcpvdzi'. Its registrable label 'devwatchalerts' stretches across 14 characters split between 4 vowels and 10 consonants. Word splitting yields three words: dev, watch, alerts. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://check-qcpvdzi.devwatchalerts.cyou/?address=BUF5RkVevNXn4VpPYPToeXm75WE1qFAurLfQwSYGpump

Page Load Overview

16.41s
Total Load Time
422 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,685 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4192.178.183.95Google · CDNUnited States
AS15169Google LLC
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
3104.18.34.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.64.151.87Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
196--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T191E2E5B2A214A039F437D4C2B6C467EF70A49407EC2746ACEED4965DC6CBEF35A20758

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:kYMI0b02EVuRIhnATIeee24ollu7pAVJnoLvwIAlq8e:DL2AVuRfeq8e

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33362:GQBUDCMDUYQSDBh4NCEgZNIQEoBAzA0sAEpWUYxkBIQQ6UFE8LgBSAio6sGAAo4KwQYoBTFCxDMAqQhFQIAJoDOw8GgCQIim

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:8000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#92e06c

Other Hashes

Crop Resistant:8000000000000000

Scan History

Scan history not available

Unable to load historical scan data