Security Scan Report: newindiacurrymahal-com.xlg.gpe.mybluehost.me

Submitted: Dec 4, 2025, 2:40:36 AMCompleted: Dec 4, 2025, 2:41:20 AMpubliccompleted
Loading additional data...

Summary

This website contacted 21 IPs in 3 countries across 6 domains to perform 19 HTTP transactions. The main domain is newindiacurrymahal-com.xlg.gpe.mybluehost.me.

Submitted URL: https://newindiacurrymahal-com.xlg.gpe.mybluehost.me/.wp-upgrade/saiga/h0thailphscrp.html

The Cisco Umbrella rank of the primary domain is #99,570 of the top 1 million websites

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site harvesting credentials; avoid and report.

Risk Factors
Malicious Indicators of Compromise present
Credential harvesting form (email + password)
New/unknown domain age
Hidden fields used for data exfiltration
Impersonation of a sign‑in page
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(36%)

Domain Information

Within the Montenegrin country-code top-level domain (.me), 'newindiacurrymahal-com.xlg.gpe.mybluehost.me' is registered; it also runs on subdomain 'newindiacurrymahal-com.xlg.gpe'. The core label 'mybluehost' covers 10 characters containing 3 vowels alongside seven consonants. Tokenizing the label suggests three words: my, blue, host. Median word length comes out to 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://newindiacurrymahal-com.xlg.gpe.mybluehost.me/.wp-upgrade/saiga/h0thailphscrp.html

Page Load Overview

1.35s
Total Load Time
19
HTTP Requests
6
Domains
98 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:401 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software36% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
36%
finance banking
28%
government public service
27%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
713.107.246.45United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
5162.241.218.61Phoenix, Arizona, United States
AS46606UNIFIEDLAYER-AS-1
3104.126.37.161Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2151.101.194.137San Francisco, California, United States
AS54113FASTLY
1195.80.159.133Saint-Ouen, Île-de-France, France
AS29152Decknet SARL
1104.17.24.14United States
AS13335CLOUDFLARENET
0104.126.37.178Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
0151.101.2.137San Francisco, California, United States
AS54113FASTLY
013.107.246.44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
02620:1ec:bdf::44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
1921--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14134845F59B228094C13A5796EF859013331E023C91EFC597E9C96A8CF8D748DEF2B89

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:H76CBaxBQAw/ATJCERu8NQl8KDwAr6fg4d6JsDjOwBWlg5oRxHDpiFeFc:5kiYO91rjpiFeFc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:230946:EAUuCZMBoGOwIKABBhjgEIGsBbIiNhuZaEhmcIJkkAoImwCAKCAkOkUqEZCBlgAZ4yyIaAIIkCAMXBoGAQHHIFFACwQ0QSEC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:013d3d0101011100
Perceptual Hash:8add0c73327632cd
Difference Hash:457171cdf159d745
Wavelet Hash:013d3d3d3d3f3301
Color Hash:#3a7778

Scan History

Scan history not available

Unable to load historical scan data