Security Scan Report: dorevilokpadjghs.com

Redirected to:
https://galootapprehension.xyz/?k=ecea79cb6520e1e3d1d8789b5af025a5.178...
Site favicon
Submitted: Sep 17, 2026, 8:47:38 AMCompleted: Sep 17, 2026, 8:48:04 AMpubliccompleted

This website contacted 1 IP in 1 country across 2 domains to perform 3 HTTP transactions. The main domain is galootapprehension.xyz and was registered 2 months ago.

Submitted URL: https://dorevilokpadjghs.com

Effective URL:

https://galootapprehension.xyz/?k=ecea79cb6520e1e3d1d8789b5af025a5.178...
Redirected

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Domain dorevilokpadjghs.com is flagged as a Latrodectus malware loader by 2 corroborated feeds and redirects through a decoy page to galootapprehension.xyz. No forms, but treat as malicious: do not visit or click through.

Risk Factors (4)
Multi-source corroborated malware indicator (latrodectus loader) tied to the scanned domain
Cross-domain redirect with obfuscated/base64 tracking parameter
Decoy 'no offers available' page with no substantive content
New (65-day-old), unranked domain on a frequently abused TLD
Domain age information unavailable

Details

Page Title

No Offers Available...

Scan Type

public

Domain Name Analysis

Domain 'dorevilokpadjghs.com' uses the commercial generic top-level domain (.com) without a subdomain. The second-level label 'dorevilokpadjghs' is 16 characters long holding 5 vowels versus eleven consonants. Segmentation suggests six words: dor, evil, ok, pad, j, ghs. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dorevilokpadjghs.com

Page Load Overview

4.04s
Total Load Time
2 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:68%
Script:Latin
Direction:ltr

Detection Details

Text Length:13 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content48% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

adult content
48%
healthcare medical
40%
e-commerce shopping
40%
real estate property
37%
news media journalism
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
334.196.13.28Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
31--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1291110F124148CABB1609AF7A879F13C3132CA0CEB62CDC4C18D2A9E02F4F01CA9E5D4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hqtomoZ2HN7ZosUssxKj83MxbZ3MxSsAsTLsgD:0C3Soxssxsvx2xS1sTLsi

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:938:AAAAAAAEAAAAAIAAAACAGABAAAMAAgAAAQAQAAAAAAAAAAACAAgAEAAAAAAAAIAGAAAAAAAAAAAAAAIAAACBAAAAAQAABCAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7ffffffffffff
Perceptual Hash:e666666626999999
Difference Hash:0c0c000000000000
Wavelet Hash:27273f3f00000000
Color Hash:#6ce0b1

Other Hashes

Crop Resistant:0c0c000000000000

Scan History

Scan history not available

Unable to load historical scan data