Security Scan Report: 3hz3ocvwm9.cfd

Redirected to: https://3hz3ocvwm9.cfd/auth/login?redirect=/message

Submitted: Nov 10, 2025, 8:13:59 PMCompleted: Nov 10, 2025, 8:14:57 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 0 countries across 1 domain to perform 12 HTTP transactions. The main domain is 3hz3ocvwm9.cfd and was registered NaN years ago.

Submitted URL: https://3hz3ocvwm9.cfd/

Effective URL: https://3hz3ocvwm9.cfd/auth/login?redirect=/messageRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

New, unranked site with a password‑only form – confirmed phishing scam.

Risk Factors
Credential harvesting password field without accompanying username
Domain age less than 7 days (critical)
Unranked domain with no reputation
Invalid/self‑signed SSL certificate triggering browser warning
Domain age information unavailable

Details

Page Title

Privacy error

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

phishing/scam

(40%)

Domain Information

The domain '3hz3ocvwm9.cfd' uses the .cfd top-level domain with no subdomain. Its registrable label '3hz3ocvwm9' stretches across 10 characters containing 1 vowel alongside 6 consonants; it also includes 3 digits. Splitting it apart reveals seven words: 3, hz, 3, oc, vw, m, 9. Median word length is 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://3hz3ocvwm9.cfd/

Page Load Overview

10.87s
Total Load Time
12
HTTP Requests
1
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:33 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing/scam40% confidence
Type: static
Method: structural

All Detected Categories

phishing/scam
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1247.238.240.247UnknownUnknown
121--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T148D3BF6155E60A7F181B44EB729B39493B686083A603EDD3F5FCB8409F8F2B52452BCD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:9mqWZAdOo9La2g+nfKBb7N7w9oMq5pchzJGu4lWQK3wmgdPup:fWWxAYgd2p

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:135072:oQHuK4VRoIgAFoalMgAJzILDTRIIANTIECIgnYSiIEFwZ+iAUAFCqkArSlACDx4gA4SIAARiAEMXzEIOqwEZAWQAUmwAgLAN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc7c7c3f3ffff
Perceptual Hash:b0339bcc6c936764
Difference Hash:001c1c1c16060000
Wavelet Hash:3f0f0703033f0f0f
Color Hash:#86372d

Other Hashes

Crop Resistant:001c1c1c16060000

Scan History

Scan history not available

Unable to load historical scan data