Security Scan Report: covencle.com

Site favicon
Submitted: Sep 14, 2026, 1:47:37 PMCompleted: Sep 14, 2026, 1:49:22 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

New (37-day) unranked Indonesian slot/gambling site reusing scraped Samsung content; primary domain carries a single-source DCRat malware indicator. No password/payment capture seen, but avoid sign-up or login.

Risk Factors (4)
Primary domain flagged in threat intelligence as a malware family (DCRat) indicator
Very new domain (37 days) operating an unlicensed slot/gambling portal
Aggregates scraped third-party (Samsung) brand content and login markup on an unrelated domain
Login/Sign-Up and 'NEMO138 LOGIN' account buttons on an unranked, brand-new host
Domain age information unavailable

Details

Page Title

NEMO138: Authentic Spin Jackpot Slot Bonus

Scan Type

public

Domain Name Analysis

The domain name 'covencle.com' uses the commercial generic top-level domain (.com). The core label 'covencle' covers 8 characters with 3 vowels and 5 consonants. Tokenizing the label suggests two words: coven, cle. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://covencle.com

Page Load Overview

75.51s
Total Load Time
13.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:42%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:id-ID
Text Length:25,263 chars
Detector Agreement:80%
Language mismatch: Declared as id-ID but detected as en

Website Classification

Primary Category

e-commerce shopping51% confidence
Type: webapp
Method: ml+structural

All Detected Categories

e-commerce shopping
51%
e-commerce
20%
forum
20%

Detected Features

Search
Products
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10172.217.119.4Google · CDNUnited States
AS15169Google LLC
6104.16.79.73Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.251.155.119Google · CDNUnited States
AS15169Google LLC
613.226.244.122Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
62.23.245.90Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
6188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
691.148.168.168Bulgaria
AS57344Telehouse EAD
672.246.28.116Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
6142.251.156.119Google · CDNUnited States
AS15169Google LLC
6172.217.114.4Google · CDNUnited States
AS15169Google LLC
13622--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T107F16393D11C4E3C32D0554AFFA5B509C3DB29398906FCA2F584052A3BE87E64677F8A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:RpXL575GENPJkTxLErLk39CUKm8xDvo8xZF8xk8xYO3/O4/H/m/vs/vVyDDi8xCx:zl1G2kFqFiDredyosb/P35fHJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7483:hEgN04IYAI4EQoKIKAAACYECBwYBECUgASUQS8IgG7oAJ8QapiDqCkYIIACJASRVIXRdUScgBAmRCKIEMoAWiQQEQQkBChLD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffef8087878781d8
Perceptual Hash:bec1cbb4843e4a5a
Difference Hash:091d393e3e3e1d31
Wavelet Hash:ffe7808787878198
Color Hash:#1f8d93

Scan History

Scan history not available

Unable to load historical scan data