Security Scan Report: rempel.mereanreng.org

Redirected to:
http://rempel.mereanreng.org/[email protected]
Site favicon
Submitted: Feb 8, 2026, 5:58:35 AMCompleted: Feb 8, 2026, 6:00:04 AMpubliccompleted

This website contacted 3 IPs in 1 country across 3 domains to perform 11 HTTP transactions. The main domain is rempel.mereanreng.org and was registered 1 year 6 months ago.

Submitted URL: http://rempel.mereanreng.org/redirect.html/?n=b2Q9MXN5cTY5N2I4ZTA1YjQ2MWN0MHRfb3V0dmxfc2hhcmVk&k=M3Zob2s%3D&r=QTAwMDByZnVlNDUycTVuMDJyX3g1MTU5Nw%3D%3D&j=ZnVlNDU%3D&u=&q=X3g1&y=X3g1&v=&o=X3g1&e=&b=ZnVlNDU%3D&m=&w=&c=MDFlN3QtMzh1dXN0MA==4g2s3U

Effective URL:

http://rempel.mereanreng.org/[email protected]
Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Known Snowshoe spam-mailer kit: a pre-filled unsubscribe page used to confirm live email addresses for bulk spam. Avoid submitting any address.

Risk Factors (5)
Known malicious spam-mailer kit identified by analyst-vetted kit roster.
Pre-filled unsubscribe page used to confirm live email addresses for spam sending.
Email address is passed in the final URL query string to an out.php endpoint.
Multiple redirects obscure the final spam-infrastructure destination.
YARA high-precision hit for Snowshoe_Mailer_Kit_Unsubscribe_Page.
Domain age information unavailable

Details

Page Title

Unsubscribe

Scan Type

public

Domain Name Analysis

Domain 'rempel.mereanreng.org' uses the non-profit oriented generic top-level domain (.org); it also runs on subdomain 'rempel'. Count 10 characters in 'mereanreng' split between 4 vowels and six consonants. Splitting it apart reveals 4 words: mere, an, ren, g. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://rempel.mereanreng.org/redirect.html/?n=b2Q9MXN5cTY5N2I4ZTA1YjQ2MWN0MHRfb3V0dmxfc2hhcmVk&k=M3Zob2s%3D&r=QTAwMDByZnVlNDUycTVuMDJyX3g1MTU5Nw%3D%3D&j=ZnVlNDU%3D&u=&q=X3g1&y=X3g1&v=&o=X3g1&e=&b=ZnVlNDU%3D&m=&w=&c=MDFlN3QtMzh1dXN0MA==4g2s3U

Page Load Overview

8.86s
Total Load Time
97 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

Text Length:209 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service33% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
33%
adult content
32%
news media journalism
29%
entertainment media
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3142.251.141.67United States
AS15169Google LLC
3142.251.141.106United States
AS15169Google LLC
346.21.153.185Los Angeles, California, United States
AS29802HIVELOCITY, Inc.
113--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F741BB1544F224721083A0A2BFE22D169E91E907961B140435FD4BEE2FE3E9BCC835AD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:koowahgwSlfwNvLjihuZCXXDYPEX0jxTxZj:bG2aZuAID9kjx3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1937:AAAAAAAAECAAWAgCAAAAQBAAAKAAMQCIAABEAMAAAgAAVAAIAAACgAABUCAIAAAhAQAAhgAEAAAAABAEAABCATAABAAAAIAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffbfffffffff
Perceptual Hash:9f3f61411f1f6061
Difference Hash:c020066a60000000
Wavelet Hash:009f818190f0f0f0
Color Hash:#53acab

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data