Security Scan Report: americandreamlost.com

Site favicon
Submitted: Sep 22, 2026, 12:41:24 PMCompleted: Sep 22, 2026, 12:41:50 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed ClickFix/FakeCAPTCHA malware delivery: clipboard-injected Windows shell command, CRITICAL AMOS loader IDS alerts, and corroborated threat-intel hits. Do not interact.

Risk Factors (6)
Known malicious ClickFix/FakeCAPTCHA kit confirmed by roster + YARA + behavioral clipboard injection
Clipboard hijacking stages a Windows shell command (powershell/msiexec) for user execution
CRITICAL network IDS alerts for AMOS ClickFix loader and EtherHiding exfiltration
Threat-intel matches on both the primary domain and a loaded third-party domain (interseq.at, 3 feeds)
Blockchain RPC endpoint (polygon-bor-rpc.publicnode.com) contact alongside a fake CAPTCHA lure
eval() dynamic code execution and unusual external .pw/.life domains loaded by the page
Domain age information unavailable

Details

Page Title

American Dream Lost – Assisting victims of the legal system

Scan Type

public

Domain Name Analysis

The domain 'americandreamlost.com' uses the commercial generic top-level domain (.com). The second-level label 'americandreamlost' is 17 characters long holding 7 vowels versus ten consonants. Breaking it apart gives three words: american, dream, lost. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://americandreamlost.com

Page Load Overview

6.82s
Total Load Time
5.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:894 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software86% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
86%
documentation technical
67%
phishing scam
47%
adult content
44%
government public service
43%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
20104.244.124.24United States
AS22611InMotion Hosting, Inc.
12192.178.170.95Google · CDNUnited States
AS15169Google LLC
12193.233.201.114Vienna, Vienna, Austria
AS210644Aeza Group LLC
12104.18.22.83Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12104.18.23.83Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12104.21.3.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12142.251.152.4Google · CDNUnited States
AS15169Google LLC
12142.251.156.4Google · CDNUnited States
AS15169Google LLC
12142.251.127.94Google · CDNUnited States
AS15169Google LLC
21217--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1617184773A8A980A29E204F3F56F7B0D7E1A510711C5AD73C989E9B42539FE5C0B7C09

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:jzIX5PEl0YDRODEKxVKqRmbUI2UIjHE5aw0ftS6/ZKd5VRIvpJ+kkk2SmMUmlmME:jUX5POnDRODESVLRmms0ftTifiZtgzV1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3554:AsECAAjAECBGOMEgAACYFQUgBgEAAgIcAAUAIIQAAEABhQNAAABEIAAAAAARpBAAQAAAIAkAQAWACQAAgCFAibSAQwAAECEA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cfc3c3ffffffffe7
Perceptual Hash:b03032cfc7cdcccc
Difference Hash:189e16100000000c
Wavelet Hash:3f030f0f0f0f3f03
Color Hash:#78763a

Other Hashes

Crop Resistant:189e16100000000c

Scan History

Scan history not available

Unable to load historical scan data