Security Scan Report: verification.diro.me

Site favicon
Submitted: Nov 14, 2025, 6:32:11 AMCompleted: Nov 14, 2025, 6:32:29 AMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 2 countries across 3 domains to perform 9 HTTP transactions. The main domain is verification.diro.me and was registered NaN years ago.

Submitted URL: https://verification.diro.me/

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

Impersonates VFS Global on an unranked domain; high‑risk phishing site.

Risk Factors
Brand impersonation on an unranked, unrelated domain
Potential typo‑squatting / deceptive subdomain mimicking a trusted service
Domain age information unavailable

Details

Page Title

VFS Global - Document Verification

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government public service

(48%)

Domain Information

The domain 'verification.diro.me' uses the Montenegrin country-code top-level domain (.me) and includes subdomain 'verification'. The registrable portion 'diro' spans 4 characters with 2 vowels and two consonants. It segments into 2 words: dir, o. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://verification.diro.me/

Page Load Overview

2.67s
Total Load Time
9
HTTP Requests
3
Domains
358 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:815 chars
Detector Agreement:75%

Website Classification

Primary Category

government public service48% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
48%
finance banking
48%
documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
034.96.86.49Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
0151.101.2.217San Francisco, California, United States
AS54113FASTLY
0185.158.133.1Frankfurt am Main, Hesse, Germany
AS13335CLOUDFLARENET
02a04:4e42::729United States
AS54113FASTLY
02a04:4e42:600::729United States
AS54113FASTLY
0151.101.66.217San Francisco, California, United States
AS54113FASTLY
02a04:4e42:400::729United States
AS54113FASTLY
02a04:4e42:200::729United States
AS54113FASTLY
0151.101.130.217San Francisco, California, United States
AS54113FASTLY
0151.101.194.217San Francisco, California, United States
AS54113FASTLY
910--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BFC2EB80344C01387E2FD655AAD8A72CA135F442EE964429B14D109EDBD3FF936EFB98

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:6b2M5TBT0W3frriPABFpNF8ieccxksc64Jysq7vGZkYNDSk4:m0W3frrxzNFmx/c64Jysq7vqDSk4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26513:ZywRAmAFSJAARkQoHkPYUNQRg7TA8CJAGCCAAgERCHCwLCALASAg4UAAwBted4EDOY0MGgpNksrYJoCCA5AQAUbBSGQCkqAo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bf9b8187bfffffff
Perceptual Hash:b73fc9c8962262c9
Difference Hash:62330f0d308c0000
Wavelet Hash:bf88808080c0f0f0
Color Hash:#84931f

Other Hashes

Crop Resistant:62330f0d308c0000

Scan History

Scan history not available

Unable to load historical scan data