Security Scan Report: www.yzliuyuan.com

Site favicon
Submitted: Sep 20, 2026, 1:49:21 PMCompleted: Sep 20, 2026, 1:49:41 PMpubliccompleted

This website contacted 2 IPs in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is yzliuyuan.com and was registered 4 years 10 months ago.

Submitted URL: https://www.yzliuyuan.com/?token=pqr0vMBUuMC1TwzZbezLvMCJTMCH52Aa

AI Security Verdict

High Risk

Confidence: 62%

7
Risk Score

Scare-lure 'Account Suspension' text paired with an unbranded enterprise-email login form and tokenized URL indicates likely credential phishing; aged domain and zero IoC/YARA/IDS hits lower confidence, so treat as high risk.

Risk Factors (5)
Account-suspension scare tactic combined with credential collection
Login/credential form on an untrusted, unbranded enterprise-email page
Unranked domain (no Cisco Umbrella top 1M reputation)
Tokenized URL suggesting targeted campaign distribution
No verifiable organization identity behind the email-login portal
Domain age information unavailable

Details

Page Title

企业邮箱 · 安全登录

Scan Type

public

Domain Name Analysis

Domain 'www.yzliuyuan.com' uses the commercial generic top-level domain (.com), featuring subdomain 'www'. Count 9 characters in 'yzliuyuan' with 4 vowels and 5 consonants. Breaking it apart gives three words: yz, liu, yuan. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.yzliuyuan.com/?token=pqr0vMBUuMC1TwzZbezLvMCJTMCH52Aa

Page Load Overview

0.78s
Total Load Time
11 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-CN
Text Length:241 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business57% confidence
Type: webapp
Method: ml+structural

All Detected Categories

corporate business
57%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1172.67.200.247Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.21.21.234Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
22--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T169112F46EA44001DB4D64198FE66A2997BA680F0A15A0B2C7CC9D535C39DB28C9FF06C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hR/C0A4UVHrk+G93hI4S0qX46bv4pUjka:TcvN49x19iFwpUt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:867:ACAAAQAAIBhEAAAACAAAAAAAAIAAAAABAAAgAAAAAAAAAAAAAAACAAACAAAAAAAAAAAAAAAEAABAAAAAAEQwCAAAABAAAAEA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c7fff7ffffffff
Perceptual Hash:b333332666cecc89
Difference Hash:0c1c100400000000
Wavelet Hash:04043c14f0f0f0f0
Color Hash:#86842d

Other Hashes

Crop Resistant:0c1c100400000000

Scan History

Scan history not available

Unable to load historical scan data