Security Scan Report: payflowlink.paypal.com

Submitted: Jul 22, 2026, 10:45:18 AMCompleted: Jul 22, 2026, 10:46:50 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is payflowlink.paypal.com and was registered NaN years ago.

Submitted URL: https://payflowlink.paypal.com

The Cisco Umbrella rank of the primary domain is #1,990 of the top 1 million websitesTop 10K Site

AI Security Verdict

Safe Website

Confidence: 95%

0
Risk Score

AI analysis skipped: Low-risk scan (score=24) on well-ranked domain #1,990.

Safety Factors
Well-established domain (ranked #1,990)
No forms or interactive credential elements
No IoC, YARA, or IDS alerts
Domain age information unavailable

Details

Page Title

Payflow Link

Scan Type

public

Language

🇺🇸

English

(55% confidence)

Category

finance banking

(56%)

Domain Information

Within the commercial generic top-level domain (.com), 'payflowlink.paypal.com' is registered, featuring subdomain 'payflowlink'. The second-level label 'paypal' is 6 characters long holding 2 vowels versus 4 consonants. Word splitting yields 1 word: paypal. Median word length comes out to six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://payflowlink.paypal.com

Page Load Overview

3.42s
Total Load Time
6
HTTP Requests
1
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:55%
Script Type:Latin
Text Length:161 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking56% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
56%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
666.211.169.120United States
AS17012PayPal, Inc.
61--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17EE07DFF1459040912221D60ECD2BB59CDE0084BF0486C00305C30FC9BD9708D8C7784

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:qzxO96ZO3kS9mMRn6QcjWR0NNEXW0YXFIUjM1GTfFoZRlGLD2wT/qzq4Bn2FA7a:kxPZaoMRn6QclfVI2MsTaZRln+w2FAu

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:16c3a25743bb4b3dce02f30a1f673c91

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:8f0f0f0f0f0f0f0e
Difference Hash:6000000000000000
Wavelet Hash:00ffcfcf00000000
Color Hash:#842d86

Other Hashes

Crop Resistant:6000000000000000

Scan History

Scan history not available

Unable to load historical scan data