Security Scan Report: id8649-oauth-colnbase-privacy-and-security.shd.yar.mybluehost.me

Submitted: Oct 30, 2025, 1:18:56 AMCompleted: Oct 30, 2025, 1:21:59 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 1 country across 2 domains to perform 10 HTTP transactions. The main domain is id8649-oauth-colnbase-privacy-and-security.shd.yar.mybluehost.me.

Submitted URL: https://id8649-oauth-colnbase-privacy-and-security.shd.yar.mybluehost.me/app?page=signin&unique=6a594acd23c2fb16fd3cdab06fde167c

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Confirmed phishing site impersonating Coinbase; avoid and report.

Risk Factors
Brand impersonation on an unranked, newly registered domain
Domain age appears to be less than 7 days
Credential‑harvesting login form (email field) on a suspicious domain
Domain age information unavailable

Details

Page Title

Coinbase - Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

e-commerce

(41%)

Domain Information

Within the Montenegrin country-code top-level domain (.me), 'id8649-oauth-colnbase-privacy-and-security.shd.yar.mybluehost.me' is registered with subdomain 'id8649-oauth-colnbase-privacy-and-security.shd.yar'. The registrable portion 'mybluehost' spans 10 characters containing three vowels alongside 7 consonants. Segmentation suggests 3 words: my, blue, host. Median word length comes out to 4 characters. The linguistic tilt is Afrikaans for 'my'. You will also see it in English and Chinese (Pinyin) contexts. Taken together, it feels Afrikaans.

Screenshot

Security scan screenshot of https://id8649-oauth-colnbase-privacy-and-security.shd.yar.mybluehost.me/app?page=signin&unique=6a594acd23c2fb16fd3cdab06fde167c

Page Load Overview

6.94s
Total Load Time
10
HTTP Requests
2
Domains
278 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:304 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce41% confidence
Type: static
Method: ml+structural

All Detected Categories

e-commerce
41%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9172.64.152.241United States
AS13335CLOUDFLARENET
2104.18.35.15United States
AS13335CLOUDFLARENET
22a06:98c1:3105::6812:230fUnited States
AS13335CLOUDFLARENET
22606:4700:440a::ac40:98f1United States
AS13335CLOUDFLARENET
150.6.18.122Phoenix, Arizona, United States
AS31898ORACLE-BMC-31898
105--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E1B2BAF0C2F268B93507C7A052B0555E3988D4139F9905C8B7AE16A26F8BCEDC4BBDD4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:xTI/9c6vRlomp5X0DJgXulwzAJOja1rrt:xT8/90GXdqd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24455:LRBMURBgQwhjsoCBAKIAUNBCCZo1HQEJARMAEZuUniMggg5ZECqow54EhMTIeMwJEKpnSMChRFkBHKKgwY8G0mADAxFsBaIo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data