Security Scan Report: villagroup.online

Redirected to: https://villagroup.online/

Site favicon
Submitted: Jan 29, 2026, 1:12:55 PMCompleted: Jan 29, 2026, 1:14:16 PMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 9 domains to perform 1 HTTP transaction. The main domain is villagroup.online and was registered NaN years ago.

Submitted URL: http://villagroup.online/

Effective URL: https://villagroup.online/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed scam – credential harvesting on a brand‑new domain.

Risk Factors
Credential harvesting form on a domain <7 days old
Password field without accompanying username field
Newly registered domain (critical risk category)
Domain age information unavailable

Details

Page Title

Emergent | Fullstack App

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(80%)

Domain Information

Domain 'villagroup.online' uses the modern generic top-level domain (.online) and has no subdomain. The core label 'villagroup' covers 10 characters with 4 vowels and 6 consonants. Tokenizing the label suggests two words: villa, group. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://villagroup.online/

Page Load Overview

2.98s
Total Load Time
28
HTTP Requests
10
Domains
2.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:234 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software80% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
80%
finance banking
75%
documentation technical
52%
gambling betting
38%
cryptocurrency blockchain
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4108.138.7.15Sweden
3172.217.16.163Sweden
3172.217.208.95Sweden
3185.199.111.133Sweden
3162.159.142.117United States
AS13335Cloudflare, Inc.
334.110.232.196Kansas City, Missouri, United States
AS396982Google LLC
3104.20.17.167United States
AS13335Cloudflare, Inc.
3104.16.79.73SwedenUnknown
3146.75.122.208SwedenUnknown
289--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A5322A316805693AD5539AD8F2F5F32E353FA316C767C6D8E1B845B463C2EC388139A8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:aGBcqRa7KBku+6tXScXGWOBlY6uoWfr4cW7r9KoGUgD7MFYnx/j0azZ9:nBayXfXGRBlY7oWE8nx/jVZ9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10996:E5MYCJGTIjNCiUiHkYkwGCwSOgAUAIYoRyAGogEE4oFkQCsMCAqAqAJAURNFCFImgCX4Z4R2qz8iEREhI0BGBBKwiOkTYTBY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c0e0e0e0e4e0e6e6
Perceptual Hash:f609347b008f6bb6
Difference Hash:018101830c0c0c0c
Wavelet Hash:e0e0e0f0f4e4e6e6
Color Hash:#8bd279

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data