Security Scan Report: ortto.message.elskling.no

Site favicon
Submitted: Sep 14, 2026, 2:12:54 PMCompleted: Sep 14, 2026, 2:13:14 PMpubliccompleted

This website contacted 19 IPs in 2 countries across 8 domains to perform 33 HTTP transactions. The main domain is ortto.message.elskling.no and was registered 7 years ago.

Submitted URL: https://ortto.message.elskling.no/-/m/s/preferences?k=CmVsc2tsaW5nbm8AaLnUbcqDWRCBjgBgaqf-p1pngLCiSUhqPwFm

AI Security Verdict

Low Risk

Confidence: 78%

2
Risk Score

Legitimate self-branded email preferences page for Elskling NO on Ortto infrastructure; no forms, no impersonation, no threat-intel hits — only informational SSL IDS notes.

Risk Factors
Domain is not ranked in Cisco Umbrella top 1M (weak prior only)
Safety Factors
Domain is 252 days old (over 6 months) and self-branded — title/meta match the elskling.no domain
Zero forms and zero credential/payment collection points
Standard Ortto/Autopilot email-preference infrastructure, consistent with legitimate marketing ops
No threat-intel, YARA, or Safe Browsing hits
Domain age information unavailable

Details

Page Title

Email preferences - Elskling NO

Scan Type

public

Domain Name Analysis

Domain 'ortto.message.elskling.no' uses the Norwegian country-code top-level domain (.no) and includes subdomain 'ortto.message'. Count 8 characters in 'elskling' with two vowels and six consonants. Splitting it apart reveals two words: els, kling. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ortto.message.elskling.no/-/m/s/preferences?k=CmVsc2tsaW5nbm8AaLnUbcqDWRCBjgBgaqf-p1pngLCiSUhqPwFm

Page Load Overview

2.24s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:404 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software33% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1565.9.130.50Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
13.23.106.204Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
13.73.199.118Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
165.9.130.104Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
165.9.130.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
13.23.199.68Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
165.9.130.46Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1108.138.7.97Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
13.136.207.21Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
3319--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D242CDB756E654129B42A9DD42153315D133883EECF0BCC3FCD4E81CB4B5FA98A9E298

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:hzz9sN46jUd9fj6vDD85aJxDuMmoqAXUnN2Tw4AYc:hzSK6jlHDumEAW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12818:EyKyiREEIQdsAs3UsKYYBAARowwSjJBmhSBABSTgHHSFIAQBRhTUAA0CUjgSKhSAp0nEBUqMmBZUZDUTCEIO0AiaqWFNEQgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c3c3c3c000000
Perceptual Hash:9b9b646464dd3171
Difference Hash:4869797161062001
Wavelet Hash:053d3f3f3f0f0101
Color Hash:#7b79d2

Other Hashes

Crop Resistant:4869797161062001

Scan History

Scan history not available

Unable to load historical scan data