Security Scan Report: fraud-esl-org-msg.cfd

Redirected to: http://fraud-esl-org-msg.cfd/wellsfargo.com

Submitted: Feb 3, 2026, 1:00:55 AMCompleted: Feb 3, 2026, 1:02:43 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 6 HTTP transactions. The main domain is fraud-esl-org-msg.cfd and was registered NaN years ago.

Submitted URL: http://fraud-esl-org-msg.cfd/

Effective URL: http://fraud-esl-org-msg.cfd/wellsfargo.comRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phishing site impersonating Wells Fargo on a brand‑new unranked domain; confirmed scam.

Risk Factors
Brand impersonation of Wells Fargo on a brand‑new domain
Social engineering detection by Google Safe Browsing
Excessive redirects (4)
Critical domain age (<7 days)
Unranked domain with no reputation
Domain age information unavailable

Details

Page Title

ESL Federal Credit Union - Log in

Scan Type

public

Language

🇺🇸

English

(52% confidence)

Category

documentation technical

(56%)

Domain Information

You're looking at domain 'fraud-esl-org-msg.cfd' on the .cfd top-level domain. The core label 'fraud-esl-org-msg' covers 17 characters holding four vowels versus ten consonants; bonus characters include three hyphens. Tokenizing the label suggests four words: fraud, esl, org, msg. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://fraud-esl-org-msg.cfd/

Page Load Overview

4.97s
Total Load Time
6
HTTP Requests
1
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:52%
Script Type:Latin
Text Length:183 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical56% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
56%
technology software
35%
adult content
34%
news media journalism
34%
healthcare medical
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.129.128.48Toronto, Ontario, Canada
AS54913Kamatera, Inc.
61--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C9B13F46974C190EA70161A2ED307BDE201F5D33A70A0DEAFDB2A07DF4CD6240736AAD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:VUytYBJABfWO6NVbgXJSauSCauBau2K7aQoka7Xa+8bzXKvHN22SY3VEa6EfB4IZ:m2A3OwAgpD+12HYGEJ4IBCUEQWzGXN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5116:JgAJQACmNSAAYgMQDAoVgMFCAEQBwWIIYjAgAGgFQwAgIAcAIEAAMGAAhIJhABcKpCoEABwCAEwAEIAASEkAAEQOABAcIACB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f7f9642407ee7e7
Perceptual Hash:a000828b63fcdeff
Difference Hash:c0c834968a740e0c
Wavelet Hash:7f7f1400003ce7e7
Color Hash:#56d22d

Other Hashes

Crop Resistant:c0c834968a740e0c

Scan History

Scan history not available

Unable to load historical scan data