Security Scan Report: klarna-oauthpsd3.app

Submitted: Sep 23, 2026, 10:47:28 AMCompleted: Sep 23, 2026, 10:48:22 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 60%

3
Risk Score

Inactive Cloudflare 522 error page, but the hostname 'klarna-oauthpsd3.app' deceptively borrows the Klarna brand and 'oauth' on a non-official, unranked domain — strong phishing-domain naming. Do not enter credentials.

Risk Factors (4)
Deceptive hostname impersonating the Klarna brand on a non-official domain
Unranked domain with negligible legitimacy signals
Phishing-kit-style hostname pattern (brand + oauth + random suffix)
Origin server unreachable / inactive hosting, consistent with takedown or throwaway infrastructure
Safety Factors (6)
No credential, password, or payment forms present in the captured DOM
No Indicators of Compromise or threat-intel matches against the page or its resources
No JavaScript malware (YARA) patterns and no obfuscated/exfiltrating scripts
No network IDS (Suricata) alerts
No cross-origin credential exfiltration observed
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 6 to 3
Domain age information unavailable

Details

Page Title

klarna-oauthpsd3.app | 522: Connection timed out

Scan Type

public

Domain Name Analysis

Domain 'klarna-oauthpsd3.app' uses the application-focused generic top-level domain (.app). Count 16 characters in 'klarna-oauthpsd3' split between 5 vowels and 9 consonants, along with 1 digit and one hyphen. It segments into six words: kl, arna, oauth, ps, d, 3. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://klarna-oauthpsd3.app

Page Load Overview

20.11s
Total Load Time
24 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:946 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical68% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
68%
technology software
66%
government public service
55%
cryptocurrency blockchain
52%
news media journalism
44%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17CE14272B1F512B6006381923695FB6A79E0C517CBFF449473DDC2632FAEE82A903295

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:lbDa/D2KUl0G4Fh8/G4FUVfq424Fj+skKm/jotQmHB+dWSGnRC3/XaQxx:lPa/CWey5VyjoWQ+DGnM3Cex

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6988:oHAGIYAAGIYEAhLxIOKSBIuMAEAIegAIKIgQwBZMJJTMCABiJIKQAiIzAQKCGQEFETIASDnJKQBhDEAQITAMCAQE4gBAbQAU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7cf0000d7d7f3ff
Perceptual Hash:f439b3b493653065
Difference Hash:1c3e8e822c260606
Wavelet Hash:c70e0000d6c7f3ff
Color Hash:#6053ac

Other Hashes

Crop Resistant:1c3e8e822c260606

Scan History

Scan history not available

Unable to load historical scan data