Security Scan Report: khtrip.cyou

Redirected to: https://khtrip.cyou/#/login.html

Site favicon
Submitted: Nov 3, 2025, 5:19:33 AMCompleted: Nov 3, 2025, 5:20:51 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 0 countries across 1 domain to perform 17 HTTP transactions. The main domain is khtrip.cyou and was registered NaN years ago.

Submitted URL: https://khtrip.cyou/

Effective URL: https://khtrip.cyou/#/login.htmlRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam; avoid any interaction.

Risk Factors
Newly registered domain (<7 days) with login form
Password field without accompanying username field
Hidden password field not visible to users
Unranked low‑reputation domain
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

unknown

(0%)

Domain Information

Domain 'khtrip.cyou' uses the .cyou top-level domain and has no subdomain. The core label 'khtrip' covers 6 characters with 1 vowel and five consonants. Splitting it apart reveals two words: kh, trip. Median word length is 3 characters. The linguistic tilt is Chinese (Zhuyin) for 'kh'. You will also see it in Vietnamese and English contexts.

Screenshot

Security scan screenshot of https://khtrip.cyou/

Page Load Overview

27.26s
Total Load Time
17
HTTP Requests
1
Domains
18 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:en
Text Length:45 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as zh

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17138.252.80.3UnknownUnknown
171--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1ABC1F85030A6C8CE01379BD4A6C1DD0C4F8BA36FC204D86178FC96E62FE7E56D966864

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nOCPuKusPRL4mGf4fGFAeb/3SfVu+bP3TTJrBYeKHHTCXMwoNXCTFBQ1:vRkmM4fGFA83SdD3TFrmegTCXMxi61

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6082:BAAQAAmMsB1wjRhEEQMEjOJAAkSTQIwAAAFllQAjpACa0AAAAQAJgQBMoAATLEIIlRQQVhAIGgsBIAA2WFErQBghiCKGCQxU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7ff0000ffffffff
Perceptual Hash:a323b3e2666666e4
Difference Hash:4d08714100010008
Wavelet Hash:81000000ffffffe7
Color Hash:#4062bf

Scan History

Scan history not available

Unable to load historical scan data