Security Scan Report: im-open.douyin.com.bytedns1.com

Submitted: Jan 11, 2026, 6:49:59 AMCompleted: Jan 11, 2026, 6:52:02 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is im-open.douyin.com.bytedns1.com and was registered NaN years ago.

Submitted URL: https://im-open.douyin.com.bytedns1.com

The Cisco Umbrella rank of the primary domain is #15,072 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

High‑risk phishing site impersonating Douyin; do not trust or provide any information.

Risk Factors
Brand impersonation on an unusual domain
Unsupported SSL/TLS protocol (insecure connection)
Domain age information unavailable

Details

Page Title

im-open.douyin.com.bytedns1.com

Scan Type

public

Language

🇺🇸

English

(69% confidence)

Category

technology software

(71%)

Domain Information

The domain name 'im-open.douyin.com.bytedns1.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'im-open.douyin.com'. The registrable portion 'bytedns1' spans 8 characters containing 1 vowel alongside six consonants; bonus characters include 1 digit. Tokenizing the label suggests 3 words: byte, dns, 1. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://im-open.douyin.com.bytedns1.com

Page Load Overview

6.98s
Total Load Time
2
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:69%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:69%
Script Type:Latin
Text Length:104 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software71% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
71%
documentation technical
43%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2163.181.92.205Spain
21--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T144048E77329A063986558498F05B43099F20B143F506C9BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:qfQho9PKBb9Js3q9Jzbs6tlg3SBKwdQWgceIszg2bMy8Old9:xhoC9JSqzzbs6o3Sj3gcrsM2eAT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184997:QBCEMAFcYiGEICBIgbIDMgsheIkQUiJIcSKEAhFTBQFhxcCH6IeW0CRAKEAlJQCuUjAqgARlMIPgKGWD0cxCGNEAmAJpAmUG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc7c7cfffffffff
Perceptual Hash:b131cecccc333333
Difference Hash:00181c1800000000
Wavelet Hash:ffdfc3cf00000000
Color Hash:#862d6e

Other Hashes

Crop Resistant:00181c1800000000

Scan History

Scan history not available

Unable to load historical scan data