Security Scan Report: n.hdykw.co

Submitted: Oct 9, 2026, 12:04:53 PMCompleted: Oct 9, 2026, 12:05:40 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Page openly sells a RAT: AV suppression, wallet/browser-credential/TG-session theft, keylogging and C2 failover, with a Telegram contact for the payload. Malware distribution, not a legitimate service.

Risk Factors (5)
Distributes and markets malware (RAT) for credential, wallet and session theft
Explicit antivirus evasion and persistence/persistence-recovery mechanisms
Command-and-control infrastructure with failover channels described
Keylogging, screen capture and clipboard monitoring advertised
New, unranked domain (63 days old) used as a storefront for the malware payload
Domain age information unavailable

Details

Page Title

黑洞远控 · 杀软压制 · 数据采集 · 永久在线

Scan Type

public

Domain Name Analysis

You're looking at domain 'n.hdykw.co' on the Colombian country-code top-level domain (.co), featuring subdomain 'n'. Count 5 characters in 'hdykw' with 0 vowels and five consonants. Segmentation suggests three words: h, dyk, w. The median word length lands at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://n.hdykw.co/

Page Load Overview

5.37s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-CN
Text Length:2,809 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software99% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
99%
government public service
98%
cryptocurrency blockchain
96%
phishing scam
91%
corporate business
91%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9202.162.99.96Singapore
AS152194CTG Server Limited
91--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T105B2A4B66191603671A7D8E2B464039F7588DA03DC2B4744B7FD6ED88BC2CE28E1B70D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:/z2+YKUCyfZQGhYqNw1kpAR+NA5XnJTc+CCXD4oXpZo/ovIQJXEcSkHmhKCDfKCu:/OtuGhYqNosNA5XnJTc+rp8ov5dEkHMS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24357:RCOAFiSQAUGIyAcoDZhyAiDKkQQAwgJkhOOFQJoAKwhgnNIcESR6wYDBGLIhxxHAENzEIBSAeghEgC0IIGmCAIMfQBoUZgTg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffefffff818181
Perceptual Hash:bdc32c4dc32d6c83
Difference Hash:23cc4d0ecc372717
Wavelet Hash:b9e7c7c3e7818181
Color Hash:#865c2d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data