Security Scan Report: api.nextworksriffzapp.monster

Submitted: Oct 24, 2025, 6:01:57 AMCompleted: Oct 24, 2025, 6:02:59 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 1 domain to perform 1 HTTP transaction. The main domain is api.nextworksriffzapp.monster.

Submitted URL: https://api.nextworksriffzapp.monster/?qr=cp&zqs=1b8fa73d1793027393289c1d0b6ab6d6

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

Site uses URL spoofing without legitimate content; treat as high‑risk phishing.

Risk Factors
URL manipulation (location bar spoofing) is a known phishing technique
Unranked, newly created domain with no reputation
Domain age information unavailable

Details

Page Title

api.nextworksriffzapp.monster

Scan Type

public

Language

🇺🇸

English

(51% confidence)

Category

technology software

(64%)

Domain Information

Within the .monster top-level domain, 'api.nextworksriffzapp.monster' is registered, featuring subdomain 'api'. The core label 'nextworksriffzapp' covers 17 characters with four vowels and 13 consonants. Word splitting yields 5 words: next, works, riff, z, app. The median word length lands at four characters. 'next' most often appears in Polish. You may catch it in Slovak and Dutch as well.

Screenshot

Security scan screenshot of https://api.nextworksriffzapp.monster/?qr=cp&zqs=1b8fa73d1793027393289c1d0b6ab6d6

Page Load Overview

26.59s
Total Load Time
1
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:51%
Script Type:Latin
HTML Lang Attribute:en
Text Length:223 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software64% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
64%
government public service
56%
news media journalism
54%
documentation technical
53%
healthcare medical
51%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1104.21.23.244United States
AS13335CLOUDFLARENET
02606:4700:3036::ac43:d6b4United States
AS13335CLOUDFLARENET
0172.67.214.180United States
AS13335CLOUDFLARENET
02606:4700:3032::6815:17f4United States
AS13335CLOUDFLARENET
14--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0047E77329A063986558498E057430D9F30B143B50AC9BC7ABCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:OfQho9PKBb9JsE9RHCbZgRjFtSBaw9QWgceIsz12bMy8Oldm:9hoC9J395CbZgLtSL3gcrsZ2eAk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:183785:4wIh0EMwZXwgD4CSaGJAAFUYkgA9EAolewARAZoMQlUAoAAUj7ELD2hViRiAqzsIQAzgA2ABYuYF4iQAYMp5QByAIRmCQAIq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc7d3f3ffffff
Perceptual Hash:b1319acecc6c3333
Difference Hash:00181c1606000000
Wavelet Hash:fcdcc0c00f0f0f0f
Color Hash:#2d4386

Other Hashes

Crop Resistant:00181c1606000000

Scan History

Scan history not available

Unable to load historical scan data