Security Scan Report: l2g66id111.cfd

Redirected to: https://www.baidu.com/

Submitted: Nov 11, 2025, 2:32:19 AMCompleted: Nov 11, 2025, 2:33:52 AMpubliccompleted
Loading additional data...

Summary

This website contacted 50 IPs in 0 countries across 15 domains to perform 130 HTTP transactions. The main domain is baidu.com and was registered NaN years ago.

Submitted URL: https://l2g66id111.cfd/

Effective URL: https://www.baidu.com/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

New unranked domain impersonates Baidu via redirect; classified as confirmed phishing scam.

Risk Factors
Brand impersonation on a newly registered, unranked domain
Domain age < 7 days (critical risk)
Unranked/low‑reputation domain
Redirect from suspicious domain to brand domain without being a known redirect service
Form present on a suspicious domain
Domain age information unavailable

Details

Page Title

百度一下,你就知道

Scan Type

public

Language

🇺🇸

English

(33% confidence)

Category

social media network

(33%)

Domain Information

Within the .cfd top-level domain, 'l2g66id111.cfd' is registered without a subdomain. Its registrable label 'l2g66id111' stretches across 10 characters split between 1 vowel and three consonants, notching six digits. Tokenizing the label suggests 6 words: l, 2, g, 66, id, 111. Expect 1.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://l2g66id111.cfd/

Page Load Overview

2.94s
Total Load Time
130
HTTP Requests
15
Domains
3.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:33%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:33%
Script Type:Latin
Text Length:254,969 chars
Detector Agreement:33%

Website Classification

Primary Category

social media network33% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
33%
documentation technical
32%
technology software
31%
news media journalism
30%
adult content
29%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
32123.244.92.38UnknownUnknown
2106.225.194.38UnknownUnknown
2185.10.104.115UnknownUnknown
28.210.106.179UnknownUnknown
2128.1.34.165UnknownUnknown
2183.60.227.38UnknownUnknown
2111.174.9.38UnknownUnknown
2150.138.253.38UnknownUnknown
2175.12.90.38UnknownUnknown
2103.235.47.212UnknownUnknown
13050--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FFE42A61D7652125B027C2BD7898764832758123CA538BBDFAEDB86C8BC55D263F3B0C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:HGBnB0yhhPU2y9XXDwiDTyTNv7FRbOTnTTTXTj8vr+Pq8/sT0Pu:k0SIUiDTyTNv7FRbOTnTTTXTj8vr+PqR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:712732:gQAkzBJhiKGYBiFRqngpDAcVDDRMYFYEAYmCZNYSAURJVVMIksAgEUAUIBXwRAASdkSFODERMAIECgg1gAFTOU8IInTxYBgu

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7fbffffffd381
Perceptual Hash:ed926d9619c4996c
Difference Hash:480e121e26083232
Wavelet Hash:3ec3c3c3d7d78180
Color Hash:#bf406e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data