Security Scan Report: bahasa99.com

Redirected to: blob:https://renewmindbodysoul.com/fa89e1f8-d4a5-43be-a64a-58237eac3631

Submitted: Jan 6, 2026, 10:23:42 PMCompleted: Jan 6, 2026, 10:27:41 PMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 3 countries across 9 domains to perform 12 HTTP transactions. The main domain is .

Submitted URL: https://bahasa99.com/wp-admin/email-pass/emailandpasslink.html

Effective URL: blob:https://renewmindbodysoul.com/fa89e1f8-d4a5-43be-a64a-58237eac3631Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

High‑risk phishing page harvesting DocuSign credentials; avoid interaction and report.

Risk Factors
Credential harvesting forms with disguised and hidden password fields
Brand impersonation of DocuSign on a non‑official domain
New/unranked domain with WordPress system paths
Unicode characters used to evade detection in form fields
Multiple redirects ending at a blob URL
Domain age information unavailable

Details

Page Title

DocuSign Share File

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(93%)

Domain Information

The domain name 'bahasa99.com' uses the commercial generic top-level domain (.com). The second-level label 'bahasa99' is 8 characters long containing 3 vowels alongside 3 consonants; bonus characters include two digits. Word splitting yields 2 words: bahasa, 99. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bahasa99.com/wp-admin/email-pass/emailandpasslink.html

Page Load Overview

1.84s
Total Load Time
12
HTTP Requests
9
Domains
160 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:279 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software93% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
93%
finance banking
80%
documentation technical
77%
social media network
64%
news media journalism
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3151.101.194.137United States
AS54113FASTLY
185.237.211.109Dubai, Dubai, United Arab Emirates
AS21859ZEN-ECN
187.248.119.251United Kingdom
AS203220Yahoo-UK Limited
1104.17.24.14United States
AS13335CLOUDFLARENET
1108.167.142.43Phoenix, Arizona, United States
AS46606UNIFIEDLAYER-AS-1
087.248.119.252United Kingdom
AS203220Yahoo-UK Limited
0104.17.25.14United States
AS13335CLOUDFLARENET
015.197.167.90United States
AS16509AMAZON-02
0142.250.184.234United States
AS15169GOOGLE
065.8.131.95United States
AS16509AMAZON-02
1214--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16E8523701AF2693A0145C2B936E37B097FA05147D109C4903BFCA7969FD7B8199BE2F8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24576:kqMFClPYGd5x8/8jM9l3CQ31ankHiefW5RYGd5x8/8jM9l3CQ31ankHiefW5oI:/1j/21EQ31X+5Rj/21EQ31X+5Z

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1803644:zNSAAAAKKZ0AwgwUikB4QPGNBjAAIL0gQkAUGNEhACcYAhJoBIZfAQAE7cvUAhiCiJhGFDUQ+Z6JBgUQ0FqqAIRZKBSDu5Hi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff008181f7fb9f9f
Perceptual Hash:bdbd91c2d2c2c2c3
Difference Hash:32333333a4433232
Wavelet Hash:ff818181d3f98b83
Color Hash:#784a3a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data