Security Scan Report: reply-sig.com

Redirected to: https://reply-sig.com/auth

Site favicon
Submitted: Nov 17, 2025, 10:51:51 AMCompleted: Nov 17, 2025, 10:52:27 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 11 HTTP transactions. The main domain is reply-sig.com and was registered NaN years ago.

Submitted URL: https://reply-sig.com/

Effective URL: https://reply-sig.com/authRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Highly suspicious credential‑harvesting site impersonating Reply; confirmed phishing scam.

Risk Factors
Brand impersonation on a newly registered domain
Newly registered domain (<7 days) with login form
Credential harvesting (email/password) form
Circular redirect indicating URL manipulation
Unranked domain with no reputable ranking
Domain age information unavailable

Details

Page Title

Reply Brasil - Sistema Integrado de Gestão

Scan Type

public

Language

🇵🇹

Portuguese

(80% confidence)

Category

corporate

(50%)

Domain Information

The domain 'reply-sig.com' uses the commercial generic top-level domain (.com) with no subdomain. Count 9 characters in 'reply-sig' with 2 vowels and 6 consonants, along with one hyphen. It segments into 2 words: reply, sig. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://reply-sig.com/

Page Load Overview

5.00s
Total Load Time
11
HTTP Requests
1
Domains
31 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:pt
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:pt-BR
Text Length:107 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11185.158.133.1Frankfurt am Main, Hesse, Germany
AS13335CLOUDFLARENET
111--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FB828440745C12786D3FAA24FEC4A72CA025B402EEE64466A10D148FE6D3FF536FAF95

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:UXAO8U5Q6nBOmEAUU/cxksc64Jysq7vG1sznYd:MMsnB7cxksc64Jysq7vG1sznYd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:19028:KBCwgIoAggQoICAySOHpdQQkGxhGIBCIEgGjAC0AYodECMghFsMxAZGDuKAwglIiRoZFFWEABFQpYCEVAUQB0UASILHDEuIA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f7fe7efffe6fcf8
Perceptual Hash:f38ccc23999966cc
Difference Hash:f5cc4c48584c8000
Wavelet Hash:0f1f2766ece0f0e0
Color Hash:#2d6cd2

Other Hashes

Crop Resistant:f5cc4c48584c8000

Scan History

Scan history not available

Unable to load historical scan data