Security Scan Report: pay-hoiafly.icu

Redirected to:
https://pay-hoiafly.icu/?fake_crap_for_dvmb_naive_idlots
Submitted: Jul 19, 2026, 5:51:59 AMCompleted: Jul 19, 2026, 5:53:08 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is pay-hoiafly.icu and was registered NaN years ago.

Submitted URL: http://pay-hoiafly.icu/?fake_crap_for_dvmb_naive_idlots

Effective URL: https://pay-hoiafly.icu/?fake_crap_for_dvmb_naive_idlotsRedirected

AI Security Verdict

High Risk

Confidence: 82%

7
Risk Score

The site impersonates the Holafly brand on a fresh, unranked domain and triggers a high‑severity Spamhaus IDS alert, indicating a high‑risk phishing attempt.

Risk Factors
Brand impersonation on a newly registered, unranked domain
High severity Spamhaus DROP IDS alert
New domain age multiplier (1.5x) applied
Domain age information unavailable

Details

Page Title

Holafly Checkout

Scan Type

public

Language

🇺🇸

English

(58% confidence)

Category

cryptocurrency blockchain

(73%)

Domain Information

Domain 'pay-hoiafly.icu' uses the .icu top-level domain and has no subdomain. Count 11 characters in 'pay-hoiafly' holding 4 vowels versus 6 consonants, plus 1 hyphen. It segments into 4 words: pay, hoi, a, fly. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://pay-hoiafly.icu/?fake_crap_for_dvmb_naive_idlots

Page Load Overview

1.20s
Total Load Time
13
HTTP Requests
4
Domains
143 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:58%
Script Type:Latin
Text Length:767 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain73% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
73%
finance banking
68%
e-commerce shopping
66%
government public service
45%
news media journalism
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13158.94.210.56Amsterdam, North Holland, Netherlands
AS202412Omegatech LTD
131--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DAC08CB7C021890FAB3026F8C9827894AF08920DC1321E44B6D0E2A6F448EEB848329C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3:qVZxVsws+7L9Hv8+5BQhBbZ6i83PvXE11YIIPvdHYaXEQoqa:qzxV/5VHHoB96D3ne1k9Ycw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:348fc553335bda82dffebf49122dd182

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:8000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#3a786f

Other Hashes

Crop Resistant:8000000000000000

Scan History

Scan history not available

Unable to load historical scan data