Security Scan Report: zonfhev65anki.mocha.app

Submitted: Dec 8, 2025, 7:03:46 PMCompleted: Dec 8, 2025, 7:04:04 PMpubliccompleted
Loading additional data...

Summary

This website contacted 33 IPs in 2 countries across 9 domains to perform 13 HTTP transactions. The main domain is zonfhev65anki.mocha.app and was registered NaN years ago.

Submitted URL: https://zonfhev65anki.mocha.app/#[email protected]

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing page harvesting credentials while masquerading as Google/Apple sign‑up.

Risk Factors
Hidden password field (credential harvesting)
Brand impersonation (Google/Apple) on unranked domain
Email address in URL fragment
Login form requesting credentials
Domain age information unavailable

Details

Page Title

x

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

phishing scam

(37%)

Domain Information

The domain 'zonfhev65anki.mocha.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'zonfhev65anki'. Count 5 characters in 'mocha' containing two vowels alongside 3 consonants. It segments into 1 word: mocha. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zonfhev65anki.mocha.app/#x@x.com

Page Load Overview

5.36s
Total Load Time
13
HTTP Requests
9
Domains
204 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:88 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam37% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
37%
news media journalism
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1335.157.26.135Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
098.87.66.187Ashburn, Virginia, United States
AS14618AMAZON-AES
0104.18.19.24United States
AS13335CLOUDFLARENET
065.9.175.126United States
AS16509AMAZON-02
0104.19.162.13United States
AS13335CLOUDFLARENET
0151.101.2.137San Francisco, California, United States
AS54113FASTLY
0142.250.186.106United States
AS15169GOOGLE
0151.101.194.137San Francisco, California, United States
AS54113FASTLY
0104.17.24.14United States
AS13335CLOUDFLARENET
034.117.59.81Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
1333--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E553C6AA3924485BA62D1B3ADEA771D8A7D07C1EA841445B3FDCAD40DBD107C6BF03E0

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:At8pRxbePpBrOF3v7CnJrPsDT3Qyhsm+bRxKVEVSnISSFecbRyYjz:A8GBwnEA8zH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:66137:QiSBACIASAQUKEgAgAgBpAKEDCgVCCAQ60oiBwoRolGx0OU5AQAFMngAOFgsSCToEMQlCnEJXoVIEiBEgbAIKHDwASARBJhA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffbd3d3800000001
Perceptual Hash:8ed98c376237a370
Difference Hash:7171716145752527
Wavelet Hash:fffffffd00000001
Color Hash:#1f934e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data