Security Scan Report: portal-auth-io-ndx.typedream.app

Submitted: Nov 5, 2025, 6:15:43 PMCompleted: Nov 5, 2025, 6:16:42 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 5 domains to perform 72 HTTP transactions. The main domain is portal-auth-io-ndx.typedream.app and was registered NaN years ago.

Submitted URL: https://portal-auth-io-ndx.typedream.app/

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating NDAX on an unranked domain – high risk.

Risk Factors
Brand impersonation (NDAX) on an unrelated domain
Page mimics a login page without a legitimate URL
UNRANKED domain combined with brand claims
Absence of legitimate NDAX branding or official domain
Domain age information unavailable

Details

Page Title

NDAX® | Login | Sign In to Your Account*

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

other

(73%)

Domain Information

The domain name 'portal-auth-io-ndx.typedream.app' uses the application-focused generic top-level domain (.app) with subdomain 'portal-auth-io-ndx'. The core label 'typedream' covers 9 characters split between three vowels and 6 consonants. Splitting it apart reveals two words: type, dream. Median word length comes out to 4.5 characters. Most frequently, 'type' shows up in French. You will also see it in English and Chinese (Pinyin) contexts.

Screenshot

Security scan screenshot of https://portal-auth-io-ndx.typedream.app/

Page Load Overview

27.03s
Total Load Time
72
HTTP Requests
5
Domains
479 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:2,319 chars
Detector Agreement:100%

Website Classification

Primary Category

other73% confidence
Type: static
Method: ml+structural

All Detected Categories

other
73%
legitimate website
71%
e-commerce
27%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12104.18.14.90United States
AS13335CLOUDFLARENET
4188.114.97.3United States
AS13335CLOUDFLARENET
4142.250.185.227United States
AS15169GOOGLE
4104.18.15.90United States
AS13335CLOUDFLARENET
4104.17.24.14United States
AS13335CLOUDFLARENET
4216.58.206.42United States
AS15169GOOGLE
4188.114.96.3United States
AS13335CLOUDFLARENET
42a00:1450:4001:82f::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
42606:4700::6812:e5aUnited States
AS13335CLOUDFLARENET
42606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
7216--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CB54D074102F6600C6E7CDA334CF3E037808547165A9516AEF684DECCAEB8BB53E5B5A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:3yWuW1Puy/WR/ulQ6Z5cMCFs1KM9X3q36jwtX8UPnFHuUvxt1ZMqPx840NP5iFx/:cZlhu7JX75K8Jt0Gw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:279200:BBLSwE7wBZIQA4tJA4FaIB1DIKSiBicpRpM8YJLDEQSEAiBAUQDRqJhnqggAUZCUBCUCuljmGIglooaNoAMmMUYW+gYDtcAa

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3c7efe7efefef
Perceptual Hash:b0346465dbdc9933
Difference Hash:8e8e9e9c1d1c0c1c
Wavelet Hash:c3c3c2c6c7c3c3c6
Color Hash:#bf9540

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data