Security Scan Report: bts.nhswap.com

Submitted: Jan 7, 2026, 6:40:12 AMCompleted: Jan 7, 2026, 6:41:41 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is bts.nhswap.com and was registered NaN years ago.

Submitted URL: https://bts.nhswap.com/?token=sMUT92yUigzULwyT9gza1gCKn3zLHwBa

AI Security Verdict

Safe Website

Confidence: 85%

0
Risk Score

No suspicious activity detected; site appears legitimate.

Safety Factors
Domain age of 1034 days (well‑established)
No forms or credential collection fields detected
No malicious Indicators of Compromise matches found
Domain age information unavailable

Details

Page Title

访问提醒

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

government public service

(49%)

Domain Information

The domain name 'bts.nhswap.com' uses the commercial generic top-level domain (.com) and includes subdomain 'bts'. Count 6 characters in 'nhswap' holding 1 vowel versus 5 consonants. Tokenizing the label suggests 2 words: nh, swap. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bts.nhswap.com/?token=sMUT92yUigzULwyT9gza1gCKn3zLHwBa

Page Load Overview

1.55s
Total Load Time
2
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:69 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service49% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
49%
news media journalism
37%
healthcare medical
36%
documentation technical
36%
adult content
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1172.67.199.181United States
AS13335CLOUDFLARENET
1104.21.52.137United States
AS13335CLOUDFLARENET
22--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1234136466BF345037527B8E4ABE7530625A0E017554BCC293FCC56D8CF862B985E379C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:xqu3LsUhY1WSVWkWa5M3GQF5CCJAX7h31liSy:xqu7zYZVWkWa2WQF57JiTiSy

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1990:IAgAEIAAQAAACAAAAAAAQAAEAAAFAAAAKCEABCACAQgAAACAAwAAAAAAAgQABgCBBAAIAAEAEEAYASAAAYAAgAQAAACQAIAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000003c18000000
Perceptual Hash:9bd9646699996466
Difference Hash:0000002a2a0c0000
Wavelet Hash:ccccecd8d8c0cccc
Color Hash:#79d2ad

Other Hashes

Crop Resistant:0000002a2a0c0000

Scan History

Scan history not available

Unable to load historical scan data