Security Scan Report: telenor-se-eu.1wp.site

Submitted: Aug 6, 2026, 6:09:24 PMCompleted: Aug 6, 2026, 6:10:56 PMpubliccompleted

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 2 HTTP transactions. The main domain is telenor-se-eu.1wp.site and was registered NaN years ago.

Submitted URL: https://telenor-se-eu.1wp.site/log/index.php

AI Security Verdict

Low Risk

Confidence: 92%

3
Risk Score

The site impersonates Telenor and harvests payment details, constituting a confirmed brand‑impersonation scam.

Risk Factors
Brand impersonation of a major telecom provider
Payment data collection on unrelated domain
Unranked domain with no reputation
Safety Factors
Domain age is >8 years (well‑established)
No malicious JavaScript or IDS alerts detected
Top-ranked domain (Cisco Umbrella #0, 3027 days old) with no strong malicious indicators — a login form on a household-name site is normal; risk clamped from 9 to 3
Domain age information unavailable

Details

Page Title

Telenor

Scan Type

public

Language

🇸🇪

Swedish

(35% confidence)

Category

finance banking

(87%)

Domain Information

The domain 'telenor-se-eu.1wp.site' uses the .site top-level domain, featuring subdomain 'telenor-se-eu'. The registrable portion '1wp' spans 3 characters split between zero vowels and two consonants, notching 1 digit. Word splitting yields 2 words: 1, wp. Median word length comes out to 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://telenor-se-eu.1wp.site/log/index.php

Page Load Overview

3.96s
Total Load Time
35
HTTP Requests
3
Domains
6 KB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:35%
Script:Latin
Direction:ltr

Detection Details

Language Code:sv
Detection Confidence:35%
Script Type:Latin
Text Length:101 chars
Detector Agreement:50%

Website Classification

Primary Category

finance banking87% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
87%
e-commerce
20%

Detected Features

Payment

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13104.26.0.160Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11142.251.110.95Google · CDNUnited States
AS15169Google LLC
11104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
353--

Page Statistics

35
Requests
3
Unique Domains
279.3 KB
Total Size

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T104024E0A5F8CA91DB00224CC69B9614974FE8937B55ACDE9F1BF8634BF84F8408B7469

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:i3MFgaS8KYSZSpS0jEajAvwj6iT8v55KGLLLLXjg5g/I//a4YxKrwtNvQT7w:iUljEaj6wj6iY55tLLLLzg5g/I//a4Y/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8328:AhRgMYLEgIhF4CkukyAiQEFFjDgEQZBhARAIKUhgA7YgAeqAOShWABsJYagUBIi1PUKi4wgQ0gUoQQAGyRGBCsDTXCNEALDI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffe7ff0000
Perceptual Hash:9b9964e66419b333
Difference Hash:0c3a3a324d4d3254
Wavelet Hash:fffffcfc24240000
Color Hash:#6c3a78

Scan History

Scan history not available

Unable to load historical scan data