Security Scan Report: openai-credits.com

Site favicon
Submitted: Oct 2, 2026, 12:12:27 PMCompleted: Oct 2, 2026, 12:13:03 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

CONFIRMED_SCAM: openai-credits.com is a 7-day-old domain flagged as 'ek clearfake-1' malware by 3 threat-intel feeds, hosting a fake Cloudflare/OpenAI verification wall that tricks users into pasting malicious commands into Terminal.

Risk Factors (5)
Multi-source corroborated Indicators of Compromise naming the primary domain as an exploit-kit/malware host
Brand impersonation of OpenAI on a domain that is not openai.com
Fake bot-verification challenge instructing users to paste commands into Terminal/Run dialog (ClickFix malware delivery)
Newly registered domain (7 days) combined with malicious reputation
Clipboard manipulation events during page load
Domain age information unavailable

Details

Page Title

Just a moment...

Scan Type

public

Domain Name Analysis

The domain 'openai-credits.com' uses the commercial generic top-level domain (.com) and has no subdomain. Count 14 characters in 'openai-credits' holding 6 vowels versus seven consonants; it also includes 1 hyphen. It segments into 4 words: open, a, i, credits. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://openai-credits.com/

Page Load Overview

1.37s
Total Load Time
118 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-us
Text Length:1,974 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software69% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
69%
documentation technical
69%
adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.21.5.161Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
240.114.178.124Azure · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
2172.67.133.157Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
73--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16914A310A680E31A53073B7B261DB6A4E43509AEBD607587D6CFFD14E29512FFB63A30

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:AxNP5X3DJT2PmT6PCe/T0ZERK1HqP3WQI/h+bqSC7yMJ/skdW6XzDqTxPpCBbgq7:AXeamb/C

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:199087:kIiOpCDILQCFAwoABhDggAMpMiC4UAggcVBKFgAutBvwJCAABQgsRfTACyAgjVYIjIlyAeQ+RKCVFWBBkFqABga2ABwgwAGO

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cfcfcfffffffffe7
Perceptual Hash:b83830ccc7c7c7c6
Difference Hash:109828000000000c
Wavelet Hash:38001030f3f3ffc3
Color Hash:#e06c6c

Other Hashes

Crop Resistant:109828000000000c

Scan History

Scan history not available

Unable to load historical scan data