Security Scan Report: gltfms.com

Site favicon
Submitted: Nov 25, 2025, 6:36:17 PMCompleted: Nov 25, 2025, 6:38:47 PMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is gltfms.com and was registered NaN years ago.

Submitted URL: https://gltfms.com/wp-admin/[email protected]

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing login page on a compromised WordPress site; do not enter credentials.

Risk Factors
Compromised WordPress site used for credential harvesting
Credential‑harvesting login form on suspicious domain
Brand impersonation (Roundcube Webmail) on unrelated domain
UNRANKED domain presenting a trusted service
Email address appears in URL parameter ([email protected]) to lure victims
Domain age information unavailable

Details

Page Title

Roundcube Webmail __ Welcome to Roundcube Webmail

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(49%)

Domain Information

Within the commercial generic top-level domain (.com), 'gltfms.com' is registered without a subdomain. The second-level label 'gltfms' is 6 characters long holding 0 vowels versus 6 consonants. Breaking it apart gives 4 words: g, lt, fm, s. Median word length is 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gltfms.com/wp-admin/roundcube.html?cms=je@sekure.net

Page Load Overview

2.12s
Total Load Time
2
HTTP Requests
2
Domains
824 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:115 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain49% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
49%
news media journalism
41%
technology software
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
168.178.163.30United States
AS26496AS-26496-GO-DADDY-COM-LLC
1104.17.24.14United States
AS13335CLOUDFLARENET
0104.17.25.14United States
AS13335CLOUDFLARENET
02606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
02606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
25--

Content Similarity HashesFor malware variant detection

Image Hashes

Perceptual Hashes

Average Hash:ffe7e7e7e7ffffff
Perceptual Hash:b333cccc263399cc
Difference Hash:0008080c0c000000
Wavelet Hash:3c242424273f3f3f
Color Hash:#bac587

Other Hashes

Crop Resistant:0008080c0c000000

Scan History

Scan history not available

Unable to load historical scan data