Security Scan Report: klarna-psd3update.app

Submitted: Sep 23, 2026, 3:11:52 PMCompleted: Sep 23, 2026, 3:12:45 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 67%

7
Risk Score

Hostname impersonates the Klarna payment brand with a 'PSD3 update' lure on an unranked .app domain; the site is currently erroring, but the deceptive domain itself is a strong phishing indicator.

Risk Factors (3)
Deceptive hostname impersonating the Klarna payment brand on an unrelated domain
'PSD3 update' naming used as a lure theme around a financial/payment regulation
Unranked domain with no reputation and no verifiable organization behind it
Domain age information unavailable

Details

Page Title

klarna-psd3update.app | 522: Connection timed out

Scan Type

public

Domain Name Analysis

The domain name 'klarna-psd3update.app' uses the application-focused generic top-level domain (.app) without a subdomain. Its registrable label 'klarna-psd3update' stretches across 17 characters with 5 vowels and 10 consonants, plus one digit and one hyphen. Splitting it apart reveals 6 words: kl, arna, ps, d, 3, update. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://klarna-psd3update.app

Page Load Overview

20.10s
Total Load Time
23 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:949 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software65% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
65%
documentation technical
64%
government public service
48%
cryptocurrency blockchain
42%
news media journalism
39%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.21.80.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.173.86Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18AE15371B1F51276006381923695FB6E79E0C517CBFF449873DDC2632FAEE81A943294

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:lrDa/D2KUlYSG4Fh8/G4FU7f0424FR+skKm/jotQmHB+dWS8nRC3/paQxx:l/a/C9eg7VyjoWQ+D8nM38ex

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6995:ACATCMwTEAgQAiggsd4QTENAGjHGgEQMAkIqQRRDCDgBTADCggITARQNYaDY4egoADJBdFQAxABAJjCAJSWAAkAwYWC8IagG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7cf0000d7d7f3ff
Perceptual Hash:f439b3b493653065
Difference Hash:1c3e8e822c260606
Wavelet Hash:c70e0000d6c7f3ff
Color Hash:#756ce0

Other Hashes

Crop Resistant:1c3e8e822c260606

Scan History

Scan history not available

Unable to load historical scan data