Summary
This website contacted 32 IPs in 4 countries across 31 domains to perform 97 HTTP transactions. The main domain is mediafire.com and was registered NaN years ago.
Submitted URL: https://citrusx.online/download.php?file=garena
Effective URL: https://www.mediafire.com/file/j0wg18n9imz7ep4/CT_GR53.apks/fileRedirected
AI Security Verdict
High Risk
Confidence: 85%
Page uses MediaFire branding to lure users into downloading an APK and contains a known malicious script; treat as high‑risk malware distribution.
Risk Factors
Details
Page Title
CT_GR54
Scan Type
public
Language
English
Category
corporate
(50%)Domain Information
Domain 'citrusx.online' uses the modern generic top-level domain (.online) and has no subdomain. The registrable portion 'citrusx' spans 7 characters with 2 vowels and five consonants. Splitting it apart reveals 2 words: citrus, x. Median word length is 3.5 characters. No strong language cues emerged from the frequency lists.
Screenshot

Page Load Overview
Language Analysis
Primary Language
Detection Details
Website Classification
Primary Category
All Detected Categories
Detected Features
Domain & IP Information
| Requests | IP Address | Location | AS Autonomous System |
|---|---|---|---|
| 4 | 142.251.141.130 | United States | AS15169Google LLC |
| 3 | 44.254.11.32 | Boardman, Oregon, United States | AS16509Amazon.com, Inc. |
| 3 | 172.66.148.140 | United States | AS13335Cloudflare, Inc. |
| 3 | 142.250.187.230 | United States | AS15169Google LLC |
| 3 | 104.17.147.83 | United States | AS13335Cloudflare, Inc. |
| 3 | 172.67.199.186 | United States | AS13335Cloudflare, Inc. |
| 3 | 188.114.97.3 | United States | AS13335Cloudflare, Inc. |
| 3 | 104.17.148.83 | United States | AS13335Cloudflare, Inc. |
| 3 | 104.26.9.66 | United States | AS13335Cloudflare, Inc. |
| 3 | 142.251.141.99 | United States | AS15169Google LLC |
| 97 | 32 | - | - |
Detected Technologies18
Content Similarity HashesFor malware variant detection
TLSH (Trend Micro Locality Sensitive Hash)
Security-focusedSpecialized for malware detection and similarity analysis
ssdeep (Context Triggered Piecewise Hashing)
Context-awareDetects similar content even with modifications
sdhash (Similarity Digest Hashing)
High-precisionHigh-precision similarity detection for forensic analysis
These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.
Image Hashes
Perceptual Hashes
Other Hashes
Scan History
Scan history not available
Unable to load historical scan data