Security Scan Report: sales.gracelandintlschool.com

Redirected to: blob:https://nirmanroyals.promising.co.in/88e0d75c-189c-447c-9dbb-a3a93ce259a9

Submitted: Mar 31, 2026, 8:23:25 PMCompleted: Mar 31, 2026, 8:24:46 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 3 countries across 7 domains to perform 6 HTTP transactions. The main domain is and was registered NaN years ago.

Submitted URL: https://sales.gracelandintlschool.com/wp-includes/ridic.html

Effective URL: blob:https://nirmanroyals.promising.co.in/88e0d75c-189c-447c-9dbb-a3a93ce259a9Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Phishing page impersonating CapitalOne on a compromised WordPress site; avoid and report.

Risk Factors
Brand impersonation with login form
Compromised WordPress site used for phishing
Blob URL scheme used to hide content source
Disguised password fields (type='text' with password placeholder)
Unicode evasion in form fields
Domain age information unavailable

Details

Page Title

Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(54%)

Domain Information

The domain 'sales.gracelandintlschool.com' uses the commercial generic top-level domain (.com) with subdomain 'sales'. Its registrable label 'gracelandintlschool' stretches across 19 characters containing 6 vowels alongside 13 consonants. Breaking it apart gives four words: graceland, in, tl, school. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sales.gracelandintlschool.com/wp-includes/ridic.html

Page Load Overview

2.66s
Total Load Time
9
HTTP Requests
7
Domains
90 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,565 chars
Detector Agreement:67%

Website Classification

Primary Category

finance banking54% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
54%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3192.178.183.95United States
AS15169Google LLC
163.176.8.218Frankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
123.36.162.211United States
1100.42.50.200United States
AS46606Unified Layer
1103.21.58.194Mumbai, Maharashtra, India
1151.101.194.137Unknown
1188.114.96.3Unknown
97--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B0436636619341BA9CB3CAC857EB2B463E849887E0C9D12477AC9AD84F838D5D47D3DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:Q7FSF3FuWFzF+fs8utovnh8utovWX93GXTHBrCt1WtXL/plyA7qvE6mw:yQl0WxMTvCvQe5Ct1WtXLRlyA7q86mw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:59334:GyAIHiAsFQhIIVSUhERBFAgYGDAwBIRag8Xe2KMiDIABCyI8k4xpDlBQCcHFwGgRgiPKAsAjFiYKFJxgSwoSgADoIAiRggiE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fa5bde7c3ffcfff
Perceptual Hash:b3cbcc27639c8931
Difference Hash:e968704c4d2a2c00
Wavelet Hash:7f363c2c0424df03
Color Hash:#2d7086

Other Hashes

Crop Resistant:e968704c4d2a2c00

Scan History

Scan history not available

Unable to load historical scan data