Security Scan Report: gas-origin2.galottery.com

Submitted: Oct 23, 2025, 4:10:52 AMCompleted: Oct 23, 2025, 4:11:42 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 1 HTTP transaction. The main domain is gas-origin2.galottery.com.

Submitted URL: https://gas-origin2.galottery.com/en-us/games/draw-games/powerball.html

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

Site exhibits URL spoofing and brand impersonation – treat as high‑risk phishing.

Risk Factors
URL manipulation (phishing technique)
Brand impersonation on an atypical subdomain
Unranked domain with brand name
Domain age information unavailable

Details

Page Title

gas-origin2.galottery.com

Scan Type

public

Language

🇺🇸

English

(53% confidence)

Category

gambling betting

(78%)

Domain Information

Within the commercial generic top-level domain (.com), 'gas-origin2.galottery.com' is registered; it also runs on subdomain 'gas-origin2'. Its registrable label 'galottery' stretches across 9 characters split between three vowels and 6 consonants. Breaking it apart gives two words: ga, lottery. Average segment length settles at 4.5 characters. 'ga' most strongly signals Dutch. Secondary signals appear in English and Chinese (Pinyin).

Screenshot

Security scan screenshot of https://gas-origin2.galottery.com/en-us/games/draw-games/powerball.html

Page Load Overview

12.21s
Total Load Time
1
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:53%
Script Type:Latin
HTML Lang Attribute:en
Text Length:171 chars
Detector Agreement:100%

Website Classification

Primary Category

gambling betting78% confidence
Type: static
Method: ml+structural

All Detected Categories

gambling betting
78%
documentation technical
51%
news media journalism
42%
adult content
37%
government public service
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1146.75.123.52Frankfurt am Main, Hesse, Germany
AS54113FASTLY
11--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B4047F77339A063986554498E057430DAF20B143B50AC9BC7ABCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:vfQho9PKBb9JsE9RHCbZgRjFtSBaw9QWgceIszB2bMy8OldS:whoC9J395CbZgLtSL3gcrsd2eA4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:183620:WkNDAghgLQ4EGHE+5BQAGBUIkAQCkpBgQUKoMxqCBQx2cFCCCB3AEzo6zYiQDTUeBUVQCYKUKzDGhAYAgVocCCDiedgRQDAn

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc7f3ffffffff
Perceptual Hash:a1319bcecc6c3333
Difference Hash:00181c0600000000
Wavelet Hash:ffdfc7f300000000
Color Hash:#409dbf

Other Hashes

Crop Resistant:00181c0600000000

Scan History

Scan history not available

Unable to load historical scan data