Security Scan Report: creyt.cl

Redirected to:
https://creyt.cl/centennialcws/onedrive-verify-obf.html
Submitted: Sep 26, 2026, 12:45:55 PMCompleted: Sep 26, 2026, 12:46:56 PMpubliccompleted

This website contacted 2 IPs in 2 countries across 2 domains to perform 4 HTTP transactions. The main domain is creyt.cl and was registered 35 years ago.

Submitted URL: http://creyt.cl/centennialcws/onedrive-verify-obf.html

Effective URL:

https://creyt.cl/centennialcws/onedrive-verify-obf.html
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Confirmed Microsoft OneDrive phishing page hosted on a compromised domain, flagged by Safe Browsing for social engineering; it impersonates OneDrive and harvests visitors' email via a fake shared-file gate.

Risk Factors (5)
Google Safe Browsing Social Engineering detection
Impersonation of Microsoft OneDrive brand on a non-Microsoft domain
Email-collection form behind a fake document-sharing gate
Established domain repurposed/compromised for phishing
Social-engineering urgency copy to coerce verification
Domain age information unavailable

Details

Page Title

Access your file - OneDrive

Scan Type

public

Domain Name Analysis

The domain name 'creyt.cl' uses the Chilean country-code top-level domain (.cl) while skipping any subdomain. Its registrable label 'creyt' stretches across 5 characters split between 1 vowel and four consonants. Breaking it apart gives 3 words: c, rey, t. Median word length is 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://creyt.cl/centennialcws/onedrive-verify-obf.html

Page Load Overview

4.27s
Total Load Time
18 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:426 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software53% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
53%
documentation technical
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
250.31.166.23Chicago, Illinois, United States
AS23352DEFT.COM
223.56.203.142Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
42--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18D7394EF97225CB7E846D3ECDB960044305D81EBA581CB60F29C6B0E6F940D99C9EB91

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:UkvdPPWr6RHMV0rKV7GpGcG3Gh4UbGgFarIyJiuiIPAXruYHXh7UO2gheDNEw:UIdPPWr6RAIyXk1h7UO2gfw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:80678:0IAQARMWMC4QkggEwMCo0VIIEGassh0A0CQ1gGAJB36JExQUgGIpgVSICLgJIYLRQfkcgpAYByJBJQI+ZEheIKQByQCAUeOh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bf181818180018ff
Perceptual Hash:9c1cb636b41cb699
Difference Hash:2c3222323a4c320c
Wavelet Hash:ff7e1c1c180018ff
Color Hash:#52862d

Other Hashes

Crop Resistant:2c3222323a4c320c

Scan History

Scan history not available

Unable to load historical scan data