Security Scan Report: covermymeds.com

Redirected to: https://external-us.covermymeds.health/

Submitted: Mar 26, 2026, 5:08:04 PMCompleted: Mar 26, 2026, 5:09:26 PMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 5 domains to perform 18 HTTP transactions. The main domain is external-us.covermymeds.health and was registered NaN years ago.

Submitted URL: https://covermymeds.com

Effective URL: https://external-us.covermymeds.health/Redirected

The Cisco Umbrella rank of the primary domain is #27,732 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

Site hosts a known malicious IP and uses heavily obfuscated JavaScript; treat as high‑risk malware distribution.

Risk Factors
Presence of a malicious IP address associated with the site
Critical JavaScript obfuscation indicating attempts to hide code behavior
Redirect to a different domain (external-us.covermymeds.health) without clear justification
Domain age information unavailable

Details

Page Title

CoverMyMeds

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

healthcare medical

(34%)

Domain Information

Domain 'covermymeds.com' uses the commercial generic top-level domain (.com) without a subdomain. The second-level label 'covermymeds' is 11 characters long holding 3 vowels versus eight consonants. Segmentation suggests three words: cover, my, meds. Median word length comes out to 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://covermymeds.com

Page Load Overview

2.55s
Total Load Time
16
HTTP Requests
5
Domains
48 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:488 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical34% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
466.97.160.56United States
AS396458CoverMyMeds LLC
364.239.123.65Germany
366.97.160.55United States
AS396458CoverMyMeds LLC
364.239.109.1United States
AS16509Amazon.com, Inc.
3146.75.122.217Frankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
165--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T112223317B803ED1AAF2D6C68127EAF3B98DCC53AC564DE5CC29CDA09074097B1696FD0

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:dXsGWLZu5cKY6wpn+AL6WBtYb6v2lz0SSGBciGLx13scJgP85c2cwInckcNXbcCO:dDWLZuz9qnr6WBtNv1aW+cgrW3Pu

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10429:APcCQDEEKEIEgwEAkQHFAKhLgw4wEaCfuxo0YAoBwgO43QYAQFAlQBIAEFDQxIQyKgmaMMBJBCCoBZBiDAAsCAcg7iIDzklQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000f3c7cfffffff
Perceptual Hash:b13b0f1f31e0cccc
Difference Hash:0828961e18000000
Wavelet Hash:000000c3073f3f3f
Color Hash:#87c596

Other Hashes

Crop Resistant:0828961e18000000

Scan History

Scan history not available

Unable to load historical scan data