Security Scan Report: www.republicrefund.com

Submitted: Dec 23, 2025, 2:27:09 PMCompleted: Dec 23, 2025, 2:30:33 PMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 1 country across 6 domains to perform 59 HTTP transactions. The main domain is republicrefund.com and was registered NaN years ago.

Submitted URL: https://www.republicrefund.com/

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Site likely phishing; impersonates Republic Bank and harvests credentials and SSN.

Risk Factors
Credential harvesting form (password fields) on unrelated domain
Collection of sensitive personal data (SSN) without clear purpose
Brand impersonation (Republic Bank) on a non‑official domain
Unranked domain with brand claims increases suspicion
Domain age information unavailable

Details

Page Title

Tax Refund Solutions - Republic Bank

Scan Type

public

Language

🇺🇸

English

(55% confidence)

Category

finance banking

(80%)

Domain Information

Domain 'www.republicrefund.com' uses the commercial generic top-level domain (.com) and includes subdomain 'www'. The registrable portion 'republicrefund' spans 14 characters with five vowels and 9 consonants. Splitting it apart reveals 2 words: republic, refund. Median word length is 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.republicrefund.com/

Page Load Overview

117.85s
Total Load Time
59
HTTP Requests
6
Domains
215 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:55%
Script Type:Latin
Text Length:4,421 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking80% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
80%
government public service
70%
technology software
49%
corporate business
33%
cryptocurrency blockchain
30%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1152.204.28.20Ashburn, Virginia, United States
AS14618AMAZON-AES
665.9.175.25United States
AS16509AMAZON-02
6216.26.182.11Louisville, Kentucky, United States
AS36333RBCORP
665.9.175.117United States
AS16509AMAZON-02
665.9.175.111United States
AS16509AMAZON-02
665.9.175.17United States
AS16509AMAZON-02
6216.239.34.36United States
AS15169GOOGLE
6216.58.206.40United States
AS15169GOOGLE
6142.250.186.170United States
AS15169GOOGLE
599--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F053956169F52037516352B92FADBB2A3FA38017C60E9D4035AC5BC81FC2F868D6739D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:djZgFPlscVzAUzfUF81rZvrF/sC9GYeW0V7Tq:MMdy9B1Oq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:62899:FCUAdGXAVwIhjQAlQgCiAAwSBiIgFhKKLgWKhU+0wnoGBgyA0sYAg0UoHiQA7RLw6AAAwFbEEihCQmzKwA8FYhYgQYcAQUcR

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data