Security Scan Report: 24kland1.win

Submitted: Dec 14, 2025, 10:48:43 AMCompleted: Dec 14, 2025, 10:49:35 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 1 domain to perform 5 HTTP transactions. The main domain is 24kland1.win and was registered NaN years ago.

Submitted URL: http://24kland1.win/

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

High‑risk phishing site using Google branding on a brand‑new, unranked domain.

Risk Factors
Brand impersonation (Google) on a newly registered domain
Circular redirect loop indicating URL manipulation
Critical domain age (<7 days) with brand claims
Unranked domain with high‑risk branding
Prompt to download an Android app from unknown source
Domain age information unavailable

Details

Page Title

24K

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(85%)

Domain Information

The domain '24kland1.win' uses the .win top-level domain while skipping any subdomain. The core label '24kland1' covers 8 characters containing 1 vowel alongside 4 consonants, plus three digits. Breaking it apart gives 4 words: 24, kl, and, 1. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://24kland1.win/

Page Load Overview

13.17s
Total Load Time
5
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:732 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software85% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
85%
documentation technical
65%
adult content
61%
phishing scam
27%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.21.16.16United States
AS13335CLOUDFLARENET
1172.67.209.197United States
AS13335CLOUDFLARENET
12606:4700:3036::6815:1010United States
AS13335CLOUDFLARENET
12606:4700:3033::ac43:d1c5United States
AS13335CLOUDFLARENET
54--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0551A31314F381B7037C89CB5C4E50C291BF713D1130AE9A6563A7E8EDBAD622B6B65

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:i2wXV8/KIpT9hGCwjh0jBlA3Hmzuod1S5KTUJVQj666ZW22dbhBpE:G8/KIpTmotlOmz9dc5KTUJVK22dy

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1346487:FjRNOKkEQIIaMoFgoQEzSsBJAsKoToTAQIgQuk60BCbYOODqI4AQEAqBIYohFQQp0k6BEJOIMCxoinlEhMAVLWcCwUIDZ5SE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:103c3c3c3c3c3c3c
Perceptual Hash:ce646c64646c7c79
Difference Hash:6669797969797979
Wavelet Hash:303c3c3c3c3d3d3c
Color Hash:#79d294

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data