Security Scan Report: oeesoewsere.art

Submitted: Oct 25, 2025, 12:05:43 PMCompleted: Oct 25, 2025, 12:06:36 PMpubliccompleted
Loading additional data...

Summary

This website contacted 13 IPs in 3 countries across 5 domains to perform 10 HTTP transactions. The main domain is oeesoewsere.art and was registered NaN years ago.

Submitted URL: https://oeesoewsere.art/au/login.html

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site impersonating Optus, high confidence malicious.

Risk Factors
Malicious Indicators of Compromise match (mass scanner IP)
Login form collecting credentials on a suspicious domain
Brand impersonation of Optus on an unranked domain
Unranked domain (not in Cisco Umbrella top 1M) used for credential harvesting
Recent domain registration (<1 year) with brand spoofing
Domain age information unavailable

Details

Page Title

Optus Login

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

government public service

(34%)

Domain Information

Within the .art top-level domain, 'oeesoewsere.art' is registered. The second-level label 'oeesoewsere' is 11 characters long split between seven vowels and four consonants. It segments into four words: oe, eso, ew, sere. Average segment length settles at 2.5 characters. 'oe' most strongly signals English. You may catch it in Indonesian and Dutch as well.

Screenshot

Security scan screenshot of https://oeesoewsere.art/au/login.html

Page Load Overview

22.16s
Total Load Time
10
HTTP Requests
5
Domains
246 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:695 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service34% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
34%
finance banking
27%
phishing scam
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10104.17.25.14United States
AS13335CLOUDFLARENET
0104.20.19.83United States
AS13335CLOUDFLARENET
0178.128.255.225Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
023.50.131.152Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
0172.217.18.10United States
AS15169GOOGLE
0104.17.24.14United States
AS13335CLOUDFLARENET
0172.66.155.116United States
AS13335CLOUDFLARENET
023.50.131.150Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
02606:4700:10::6814:1353United States
AS13335CLOUDFLARENET
02606:4700:10::ac42:9b74United States
AS13335CLOUDFLARENET
1013--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E952B62DB2A0006B6D53C4E7F981BA14B51591C3EE3BC6E2F98D9510BFD7AA35D83348

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ho6VhH9cn7JXeS7JXex/27xuRp7vZvnj64Xwn95lgGd6fhDJowdFB1n:h5VfuhL70jZjjy9gO6ZD5dFBh

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:13603:BG2SIVKBGRSICFCo6i1ROIABKKAwvxBECgBFLEADQMK0KVBOaEuhGhBALAQEiCCMoQ8DUyjYYQQ6AsssAglgEBGAXN0bomAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data