Security Scan Report: couponsrewards.xyz

Submitted: Sep 24, 2026, 9:47:13 AMCompleted: Sep 24, 2026, 9:47:48 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 55%

3
Risk Score

New 7-day-old crypto token rewards dashboard. No forms, no impersonation, no malware; only a single unverified phishing report on a linked Block Explorer subdomain. Speculative but no concrete malicious signal.

Risk Factors (3)
Newly registered domain (7 days old)
Single-source unverified phishing threat-intel report on a linked third-party subdomain
Crypto token site promoting yield/rewards economics with no established reputation
Safety Factors (6)
No forms of any kind — no credential, login, or payment collection
No brand impersonation: page references Robinhood Chain/Blockscout as infrastructure, not as itself
No JavaScript malware (YARA), no known phishing kit, no credential exfiltration
Site self-brands as 'COUPONS' matching its own domain
Content includes explicit disclaimers ('Nothing here is a promised yield', 'Rewards do not protect your principal')
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 3
Domain age information unavailable

Details

Page Title

COUPONS · PONS rewards

Scan Type

public

Domain Name Analysis

The domain 'couponsrewards.xyz' uses the open generic top-level domain (.xyz). Its registrable label 'couponsrewards' stretches across 14 characters with 5 vowels and nine consonants. Tokenizing the label suggests 2 words: coupons, rewards. Average segment length settles at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://couponsrewards.xyz/

Page Load Overview

0.78s
Total Load Time
617 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:4,600 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain67% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

cryptocurrency blockchain
67%
e-commerce shopping
50%
finance banking
49%
technology software
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1075.2.60.5Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
3172.64.149.113Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.67.72.116Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.26.0.65Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.26.1.65Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.38.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
318--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117D41210537A69220825D56B526F376923ACAC43D2DEF5B0F1AC98413F9BE72916F0CF

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:vVQQb/2cd8GuAVQQb/2cd8GuEPsPEryJVQQb/2cd8GuS:9QQpdvdQQpdvqPEry/QQpdvt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:604247:aADEEGTTHCFQbdSj0EJh1gnNgEIgtgKtIiAWQAKQodANkEghu4BhGXgQiIJUFJIqGDZKIRQ5HPAAjCjKIjlIMNqAB4GBg+xD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfcfcfefffc3c3
Perceptual Hash:b19b64ce648e6633
Difference Hash:929e9b9999899e9e
Wavelet Hash:cac2cfcfc1c5c1c1
Color Hash:#784f3a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data