Security Scan Report: onetex.se

Redirected to:
https://www.onetex.se/
Site favicon
Submitted: Oct 4, 2026, 10:50:13 AMCompleted: Oct 4, 2026, 10:50:57 AMpubliccompleted

This website contacted 5 IPs in 2 countries across 5 domains to perform 28 HTTP transactions. The main domain is onetex.se and was registered 13 years ago.

Submitted URL: https://onetex.se

Effective URL:

https://www.onetex.se/
Redirected

AI Security Verdict

Moderate Risk

Confidence: 60%

6
Risk Score

Closed 13-year-old Swedish baby shop with classic injected spam text promoting an investment firm ('Opportun Capital'), a sign of a compromised or abandoned site. No credential or payment forms and no threat-intel hits, so not phishing.

Risk Factors (3)
Third-party promotional/investment text injected into content unrelated to the site's own subject matter
Defunct store page still live and serving injected advertising content
External unranked script host (redistats.com) loading JavaScript
Safety Factors (5)
Domain is 13 years old (registered 2013-02-27)
No credential, login or payment fields captured on the page
No threat-intelligence matches against the page or its resources
No JavaScript malware (YARA) patterns and no network IDS alerts
No cross-origin credential submission or credential exfiltration detected
Domain age information unavailable

Details

Page Title

Nätbutiken för dop och små bebisar

Scan Type

public

Domain Name Analysis

The domain 'onetex.se' uses the Swedish country-code top-level domain (.se) and has no subdomain. The registrable portion 'onetex' spans 6 characters containing three vowels alongside three consonants. Breaking it apart gives 2 words: one, tex. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://onetex.se

Page Load Overview

9.84s
Total Load Time
2.3 MB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:57%
Script:Latin
Direction:ltr

Detection Details

Text Length:868 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking29% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
29%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8178.73.247.189Stockholm, Stockholm County, Sweden
AS42708Glesys AB
5172.67.71.71Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5104.26.8.38Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5172.67.130.174Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5104.26.9.38Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
285--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13EE23E0192F10533542A74D5A6942F1B6DB09FBFD2660428B6EC0FB17FEBDC26E93198

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:ZRIZACAVABAD2QA4AoBvX3N6lmIvthiYYeVckx75kpNKGtkxYQa8ILNQxQyEP0Yr:ZNblJ7A5E2K

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33030:gAKxUFAkJ3ElgHqFGAIc7PqWYwDBSicmCgEiJBAlCAyTYMYNwqUgKMWrACI0oUl1jIKDKAUQAAxNYgGgCEgCAgD1AhCEOLwx

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:83d3fbefc7c7c7c7
Perceptual Hash:b44d6c3966c967c1
Difference Hash:322a221e1c1c1c0d
Wavelet Hash:8083c3c3c7c7c7c7
Color Hash:#c3c587

Other Hashes

Crop Resistant:322a221e1c1c1c0d

Scan History

Scan history not available

Unable to load historical scan data