Security Scan Report: www.mstclaudens.beer

Redirected to:
https://www.mstclaudens.beer/login.php
Submitted: Sep 20, 2026, 5:47:25 AMCompleted: Sep 20, 2026, 5:47:47 AMpubliccompleted

This website contacted 5 IPs in 2 countries across 5 domains to perform 11 HTTP transactions. The main domain is mstclaudens.beer and was registered 18 years ago.

Submitted URL: https://www.mstclaudens.beer

Effective URL:

https://www.mstclaudens.beer/login.php
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Exploit-kit/credential-phishing page flagged as malicious by 3 independent threat feeds; hosts a login form on a 107-day-old unranked domain. Do not enter credentials.

Risk Factors (4)
Multi-source corroborated content-malware threat-intel match on primary domain (exploit kit / clearfake family)
Malicious host IP flagged by multiple feeds
Login form collecting username and password on a recent, unranked domain
HIGH severity IDS alert (Spamhaus DROP listed traffic)
Domain age information unavailable

Details

Page Title

RCS Panel — Login

Scan Type

public

Domain Name Analysis

The domain 'www.mstclaudens.beer' uses the .beer top-level domain and includes subdomain 'www'. The registrable portion 'mstclaudens' spans 11 characters holding three vowels versus eight consonants. Breaking it apart gives 3 words: mst, claude, ns. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.mstclaudens.beer

Page Load Overview

0.86s
Total Load Time
350 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:78 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service46% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
46%
technology software
38%
cryptocurrency blockchain
35%
news media journalism
33%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.95Google · CDNUnited States
AS15169Google LLC
2142.251.14.94Google · CDNUnited States
AS15169Google LLC
115--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D641EC11A0B00C7B51A3D5E9AADA932E3CD18017CA87991077BC9BA81F97D83C9A7549

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nBrq793QFVXiJs4G+glokgThAWv0EqLiYSUv:nBrq793QF0Js4+JWvPqLi4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2293:AAACQgIABggQAAAQIACAgIwAACEQQQBAgAAYkBAAIgBIASAAQCCAAAACAAAAAAAEAAAAAAAIAAEABIQEAIwQIAgAAAAAAEEI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:cc2333ccce339966
Difference Hash:0008103032320c10
Wavelet Hash:0c0c18181c1c0000
Color Hash:#d22d69

Other Hashes

Crop Resistant:0008103032320c10

Scan History

Scan history not available

Unable to load historical scan data