Security Scan Report: www.bqzl36.vip

Redirected to:
https://www.5xh8dn.vip:9553/register25684?i_code=73104968
Site favicon
Submitted: Sep 13, 2026, 5:47:42 PMCompleted: Sep 13, 2026, 5:48:26 PMpubliccompleted

Summary

This website contacted 4 IPs in 4 countries across 4 domains to perform 10 HTTP transactions. The main domain is 5xh8dn.vip and was registered 1 month ago.

Submitted URL: https://www.bqzl36.vip

Effective URL: https://www.5xh8dn.vip:9553/register25684?i_code=73104968Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Fake 开云体育/Real Madrid gambling portal on a non-official domain demanding account registration credentials, with a formbook malware indicator on the entry domain. Avoid and report.

Risk Factors
Brand impersonation of 开云体育 and Real Madrid football club
Credential-collecting registration form with hidden password fields
Formbook malware indicator associated with the primary domain (single-source)
Unranked, non-official domain hosting a gambling login/registration funnel
Obfuscated/generated JavaScript (Function() constructor calls)
Domain age information unavailable

Details

Page Title

部官方区域合作伙伴    开云体育官网-皇家马德里足球俱乐

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

government public service

(30%)

Domain Information

Domain 'www.bqzl36.vip' uses the .vip top-level domain with subdomain 'www'. Its registrable label 'bqzl36' stretches across 6 characters with 0 vowels and four consonants, along with two digits. It segments into three words: bq, zl, 36. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.bqzl36.vip

Page Load Overview

17.70s
Total Load Time
39
HTTP Requests
4
Domains
251 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
Text Length:126 chars
Detector Agreement:50%

Website Classification

Primary Category

government public service30% confidence
Type: spa
Method: ml+structural

All Detected Categories

government public service
30%
adult content
30%
news media journalism
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12154.220.10.112Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
9172.65.242.166Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
943.243.240.205Hong Kong
AS153494XRUI TECHNOLOGY LIMITED
914.0.58.130Cdnetworks · CDNBangkok, Bangkok, Thailand
AS54994Meteverse Limited.
394--

Page Statistics

39
Requests
4
Unique Domains
1.0 MB
Total Size

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0C23B334909B4730C3A3C9AE1E26A4E1D0CD21AD56346C8F2ACF6EAD6DEF095D1F494

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:8EhxQCp8MZHMqtah6mpYZxMU76gGBtS6x9flMjURZsVuSbxfcRBx2OcRBq3hcROL:8EhxQCp8MZHhmqdOTBtSk99MjFVuA+yE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26627:JlSwGFApEYAfKQEAIBg4GrKpglUYBICApwGwCATg9BDCECSKIA5RobAAIciMJDBQsbicqHSomE0qaBAgVAKBP1ICAUCwcTQm

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff1818181000
Perceptual Hash:cc8cb306369e9de2
Difference Hash:e0f0b2b2b2b2b0e0
Wavelet Hash:ffffff1818181800
Color Hash:#8153ac

Other Hashes

Crop Resistant:e0f0b2b2b2b2b0e0

Scan History

Scan history not available

Unable to load historical scan data