Security Scan Report: admin.plan3.aero

Redirected to:
https://login.plan3.aero/u/organization?state=hKFo2SB3V214dks5bVJDTnpG...
Site favicon
Submitted: May 9, 2026, 8:42:48 PMCompleted: May 9, 2026, 8:44:18 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 1 country across 7 domains to perform 37 HTTP transactions. The main domain is login.plan3.aero and was registered NaN years ago.

Submitted URL: https://admin.plan3.aero

Effective URL: https://login.plan3.aero/u/organization?state=hKFo2SB3V214dks5bVJDTnpGck9BT0wwcEswRDNldjh4MklEQqFutnByZS1sb2dpbi1vcmdhbml6YXRpb26jdGlk2SBTbEdUdVc2SklPc1pPMklCemR6TFhoeDB1RlBtTlFfdaNjaWTZIHpGRjRGTm9xQVFjMFBKeEs4a2xYNzlIY1J6MDBDdjlhRedirected

The Cisco Umbrella rank of the primary domain is #476,938 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 78%

9
Risk Score

The site shows a critical C2 beacon alert and heavily obfuscated JavaScript, indicating malware distribution despite lacking phishing forms.

Risk Factors
Critical IDS alert for potential C2 beacon
Highly obfuscated JavaScript with suspicious static analysis patterns
Low reputation ranking in Cisco Umbrella
Domain age information unavailable

Details

Page Title

Enter your organisation | Plan3 admin client

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government public service

(54%)

Domain Information

Domain 'admin.plan3.aero' uses the .aero top-level domain; it also runs on subdomain 'admin'. The second-level label 'plan3' is 5 characters long containing 1 vowel alongside three consonants, along with one digit. Segmentation suggests two words: plan, 3. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://admin.plan3.aero

Page Load Overview

3.72s
Total Load Time
36
HTTP Requests
6
Domains
16 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:155 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service54% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
54%
corporate business
53%
healthcare medical
43%
news media journalism
29%
cryptocurrency blockchain
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6142.251.20.95United States
AS15169Google LLC
518.64.195.35United States
AS16509Amazon.com, Inc.
518.66.147.45United States
AS16509Amazon.com, Inc.
5108.138.26.52United States
AS16509Amazon.com, Inc.
565.9.175.117United States
AS16509Amazon.com, Inc.
5104.18.34.171United States
AS13335Cloudflare, Inc.
53.167.227.55United States
AS16509Amazon.com, Inc.
367--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T143A21AC576E670B767A711F611AF240AA234A5C75C0E8A00F87EE1D43FBDA960B23D5C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:0q1QTCI9cXxzFSJmeUkHNC/7iw8uMXOoy886TAtKY9JN3P1BQjckgP5zRIiS86Ie:0qmTyZK8/2uMXXBe9ztBQmGBu4vKg

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22600:gIBDBEX0GdhJAwAIYwvETmQARbK4EwhSNGYOAa9CKBBhEehEo0LEYWvlEBQoqFEAgCmnBAmJAAgRBZmJyHOA8QYAEMYWiJXA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:cccc333333cccc33
Difference Hash:00b2b2b2b2b2b200
Wavelet Hash:00181c1c1c1c1800
Color Hash:#a12dd2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data