Security Scan Report: get.sctivated.win

Redirected to:
https://get.activated.win/
Submitted: Sep 15, 2026, 3:47:44 PMCompleted: Sep 15, 2026, 3:48:10 PMpubliccompleted

This website contacted 3 IPs in 2 countries across 2 domains to perform 3 HTTP transactions. The main domain is get.activated.win and was registered 4 months ago.

Submitted URL: https://get.sctivated.win/

Effective URL:

https://get.activated.win/
Redirected

AI Security Verdict

Moderate Risk

Confidence: 72%

5
Risk Score

Entry URL carries a single-source URLhaus malware_download Indicator of Compromise and redirects to a lookalike domain serving PowerShell activation scripts. Avoid downloading or running anything from it.

Risk Factors (4)
Content-malware Indicators of Compromise match on the primary domain (malware_download, single source)
Cross-domain redirect to a lookalike/homoglyph-style domain (sctivated.win → activated.win)
Powershell activation-script references associated with software piracy/loader distribution
No visible content, no forms, unranked domain — page exists only to redirect/load scripts
Safety Factors (5)
No credential or payment forms present (0 password fields, 0 payment fields)
No JavaScript YARA malware patterns detected
No network IDS/Suricata alerts detected
Threat-intel match is single-source and unverified
Established domain (853 days old) with no strong malicious indicators — risk clamped from 7 to 5
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain 'get.sctivated.win' uses the .win top-level domain; it also runs on subdomain 'get'. Count 9 characters in 'sctivated' with three vowels and 6 consonants. It segments into five words: s, ct, iv, a, ted. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://get.sctivated.win/

Page Load Overview

6.44s
Total Load Time
8 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:5,927 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software67% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
67%
documentation technical
52%
adult content
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
182.153.135.80Singapore, Singapore
AS61112AKILE LTD
1185.199.109.153Fastly · CDNUnited States
AS54113Fastly, Inc.
1185.199.111.153Fastly · CDNUnited States
AS54113Fastly, Inc.
33--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F1C1B829D988426F53A322BF0C599804F7EFC21F92515E44755CF4A0AFD513DC6B0BB6

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:RlIeZRyu90xh2YPzIqOTtHhpyh8GaS6dSSSLSSQ9yLiiVkGwkx4IeQ4GTY8EkLJV:TIORyu90xhp7vOMh8yZzLzoyLiiKGwS3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6060:AAEEA0IMOFJoAJkAJGhAZICAKEFCgKBES4DIAEBBIAQY5AQQWAAEgwBEhGAYA44EBkp8QlcIKAMCCAaACDCh0gEyA0CQgNiA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f1f1f0f3f0f07
Perceptual Hash:9fc54688261c8f3f
Difference Hash:60e070787ef07c6d
Wavelet Hash:3e3e1e0f073f1f00
Color Hash:#79a3d2

Other Hashes

Crop Resistant:60e070787ef07c6d

Scan History

Scan history not available

Unable to load historical scan data