Security Scan Report: listing-kxayr4ldb.orbitrelaylogs.click

Submitted: Sep 13, 2026, 3:38:39 AMCompleted: Sep 13, 2026, 3:39:01 AMpubliccompleted

This website contacted 8 IPs in 1 country across 5 domains to perform 14 HTTP transactions. The main domain is listing-kxayr4ldb.orbitrelaylogs.click and was registered 1 month ago.

Submitted URL: https://listing-kxayr4ldb.orbitrelaylogs.click/?ca=3UbuX5ADxvDcsP3jHR1ZTPWF3N6MdqUm57P3mt71eCGh

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

New 3-day-old .click domain reported for phishing, running a fake Solana token 'vote' page whose only purpose is to get visitors to connect their wallet — a classic crypto-drainer lure. Do not connect a wallet.

Risk Factors (5)
Domain registered 3 days ago with no Cisco Umbrella reputation
Single-source phishing threat-intel match on the primary domain
Wallet-connect lure with fabricated voting/points incentive (wallet drainer pattern)
No legitimate business identity, no verifiable brand ownership, no terms/contact information
Resources loaded from unrelated suspicious TLDs (.cc, .lol)
Domain age information unavailable

Details

Page Title

PONS – Pons · OrbitRelay

Scan Type

public

Domain Name Analysis

You're looking at domain 'listing-kxayr4ldb.orbitrelaylogs.click' on the .click top-level domain; it also runs on subdomain 'listing-kxayr4ldb'. Its registrable label 'orbitrelaylogs' stretches across 14 characters containing 5 vowels alongside 9 consonants. Segmentation suggests three words: orbit, relay, logs. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://listing-kxayr4ldb.orbitrelaylogs.click/?ca=3UbuX5ADxvDcsP3jHR1ZTPWF3N6MdqUm57P3mt71eCGh

Page Load Overview

1.73s
Total Load Time
500 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,714 chars
Detector Agreement:75%

Website Classification

Primary Category

cryptocurrency blockchain58% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
58%
government public service
38%
forum community discussion
36%
social media network
33%
news media journalism
33%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7172.67.172.64Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.20.95Google · CDNUnited States
AS15169Google LLC
1188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.21.96.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.110.94Google · CDNUnited States
AS15169Google LLC
1104.21.33.58Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.250.154.95Google · CDNUnited States
AS15169Google LLC
148--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17F33C75B65B32131652360AA6FEB570B33709503D20AC864BFDD53888FC6AD9D9B378C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:+Qm+t4gE+IJSSmYebLuWfbG5urZ0kPVA3VMk5373:zt4gE+VbyKu3VMkN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:51616:OFxCVCEnVgRHLARwXShOWxkMEqJClDBAGBGMASQABCiOakAKcILGAUaACrWWYprAHQqK0ACAD9CIhCtLDLwADkoJqFgQjJKi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:8000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#e06c9a

Other Hashes

Crop Resistant:8000000000000000

Scan History

Scan history not available

Unable to load historical scan data