Security Scan Report: capsysnet.vg

Redirected to:
https://www.gmx.net/consent-management/
Site favicon
Submitted: Oct 4, 2026, 11:43:52 AMCompleted: Oct 4, 2026, 11:44:37 AMpubliccompleted

This website contacted 11 IPs in 3 countries across 14 domains to perform 93 HTTP transactions. The main domain is gmx.net and was registered 14 years ago.

Submitted URL: https://capsysnet.vg/

Effective URL:

https://www.gmx.net/consent-management/
Redirected

AI Security Verdict

Low Risk

Confidence: 76%

3
Risk Score

Scanned domain capsysnet.vg carries a multi-source content-malware Indicator of Compromise (PowerShell injector); it bounces to a clean GMX consent page. The entry domain is flagged malware — avoid.

Risk Factors (3)
Multi-source content-malware Indicator of Compromise on the scanned primary domain capsysnet.vg (PowerShell injector)
Scanned domain redirects visitors off-domain to an unrelated site, a pattern often used for cloaking or to hand traffic to benign pages while some visitors receive malware
Entry domain capsysnet.vg is unranked in Cisco Umbrella while masquerading as a benign destination
Safety Factors (5)
Final rendered content is GMX's own privacy/consent management page on GMX's official gmx.net domain
No password, payment, or disguised credential fields present in the captured DOM
No JavaScript YARA matches, no IDS alerts, no obfuscated/exfiltrating script behavior observed in the capture
Established domain (10161 days old) with no strong malicious indicators — risk clamped from 7 to 5
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 3
Domain age information unavailable

Details

Page Title

GMX - kostenlose E-Mail, Cloud, Nachrichten & Freemail

Scan Type

public

Domain Name Analysis

Domain 'capsysnet.vg' uses the .vg country-code top-level domain with no subdomain. The registrable portion 'capsysnet' spans 9 characters containing 2 vowels alongside 7 consonants. Word splitting yields three words: caps, ys, net. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://capsysnet.vg/

Page Load Overview

4.08s
Total Load Time
789 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:182 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software73% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
73%
gambling betting
63%
documentation technical
63%
government public service
52%
phishing scam
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13217.72.199.68Germany
AS8560IONOS SE
880.97.160.94Moldova
AS48753Ava Host Srl
823.214.208.230Akamai · CDNLondon, England, United Kingdom
AS16625Akamai Technologies, Inc.
823.209.208.242Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
8217.72.199.24Germany
AS8560IONOS SE
8217.72.199.64Germany
AS8560IONOS SE
8217.72.199.51Germany
AS8560IONOS SE
8217.72.199.120Germany
AS8560IONOS SE
8217.72.199.145Germany
AS8560IONOS SE
8217.72.199.72Germany
AS8560IONOS SE
9311--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E4A1A6F39811C9751240A2E0A261F32D92A9F557FE80C8C4B6EC46507B85FEF68747E8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:NsyJuVUQYE2VCM7rpO97Q7vY4jC8pPINKHLcCSv8KHBvmG9kUMHUogUbqUMy5DFh:VQvYLVCM7rA97QxE6WnzM0abzMg+HsZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4951:gCiBAogCJDRjoAQEgAhYAQRORoRZgwRAgAAEEAAYgAAZhAhkAAAAQTECAABAAAQEAAQ8CATICQhRAoUINUBoogAJCAIAsQAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:91e7c7c7c7c3ffff
Perceptual Hash:b133cc6c9e396929
Difference Hash:238c9e8c8e9e96d4
Wavelet Hash:80c6c2c6c2c2dbff
Color Hash:#e06c6c

Scan History

Scan history not available

Unable to load historical scan data