Security Scan Report: sora2.org

Site favicon
Submitted: Oct 8, 2025, 2:07:40 PMCompleted: Oct 8, 2025, 2:08:45 PMpubliccompleted
Loading additional data...

Summary

This website contacted 17 IPs in 2 countries across 8 domains to perform 225 HTTP transactions. The main domain is sora2.org and was registered NaN years ago.

Submitted URL: https://sora2.org/

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

High‑risk phishing site impersonating OpenAI's Sora 2 on a new, unranked domain.

Risk Factors
Brand impersonation of OpenAI on an unusual, unranked domain
New domain (<90 days) used for brand‑related content
Lack of official OpenAI branding or verification
Domain age information unavailable

Details

Page Title

Sora 2 Wiki: Your Guide to OpenAI's AI Video Generator

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(61%)

Domain Information

Domain 'sora2.org' uses the non-profit oriented generic top-level domain (.org) with no subdomain. Count 5 characters in 'sora2' holding two vowels versus two consonants, plus one digit. Breaking it apart gives two words: sora, 2. Median word length comes out to 2.5 characters. 'sora' most strongly signals Romanian. It also appears in Sinhala and English contexts. Net impression: Romanian phrase with character flair.

Screenshot

Security scan screenshot of https://sora2.org/

Page Load Overview

15.16s
Total Load Time
225
HTTP Requests
8
Domains
4.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,363 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software61% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
61%
entertainment media
43%
adult content
38%
social media network
36%
government public service
32%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17172.66.0.227United States
AS13335CLOUDFLARENET
13216.239.32.36United States
AS15169GOOGLE
13146.75.120.157Frankfurt am Main, Hesse, Germany
AS54113FASTLY
13188.114.97.3United States
AS13335CLOUDFLARENET
13146.75.120.159Frankfurt am Main, Hesse, Germany
AS54113FASTLY
13142.250.185.72United States
AS15169GOOGLE
13104.18.36.146United States
AS13335CLOUDFLARENET
13188.114.96.3United States
AS13335CLOUDFLARENET
13172.64.151.110United States
AS13335CLOUDFLARENET
13104.18.37.127United States
AS13335CLOUDFLARENET
22517--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D1142B2B7004CE1C9C6BAD99723EBC7C804EC712C7A5C99CE6CDD52E07C19B926B65E4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:YJAsJtLCisrkBjPuYnAlRdKUDgg9cuIl/RhEEWxSy23Rt1KWEQWaX88xUDnQu:YJtLCQBjPuuRhEEWoy23oPQ9c

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:201422:zEJwTcCAICgxj7IxQ0Sn65C5grAUJ0pIhQJgmTjEBFQiVKWA4AJhQBDNACEADEAKCIADpEYEwJgF4JqQAVFQIB5hY5aIDrch

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00003c003c3c3838
Perceptual Hash:ce7169de306992c6
Difference Hash:13f4e0b365696161
Wavelet Hash:c0fc7e183c3c3c3c
Color Hash:#53ac8d

Scan History

Scan history not available

Unable to load historical scan data