Security Scan Report: xn--9kqy75h.icu

Redirected to: https://ct.gf002.sbs/web.php?from=1yfb9yx

Submitted: Nov 21, 2025, 1:34:17 PMCompleted: Nov 21, 2025, 1:37:50 PMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 1 country across 2 domains to perform 38 HTTP transactions. The main domain is ct.gf002.sbs and was registered NaN years ago.

Submitted URL: http://xn--9kqy75h.icu/

Effective URL: https://ct.gf002.sbs/web.php?from=1yfb9yxRedirected

AI Security Verdict

Low Risk

Confidence: 70%

2
Risk Score

New unranked site with no evident malicious activity; low risk.

Risk Factors
Very new domain (<30 days)
Unranked domain with low reputation
Gibberish OCR text suggesting unclear or potentially deceptive content
Safety Factors
No credential or payment forms detected
No malicious Indicators of Compromise matches found
No external links or redirects to known malicious sites
Domain age information unavailable

Details

Page Title

祥云手工坊

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

documentation technical

(74%)

Domain Information

Domain 'xn--9kqy75h.icu' uses the .icu top-level domain without a subdomain. The second-level label 'xn--9kqy75h' is 11 characters long split between zero vowels and 6 consonants, notching 3 digits and 2 hyphens. Word splitting yields 7 words: xn, 9, k, q, y, 75, h. Expect one character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://xn--9kqy75h.icu/

Page Load Overview

0.50s
Total Load Time
38
HTTP Requests
2
Domains
N/A
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:1,350 chars
Detector Agreement:67%

Website Classification

Primary Category

documentation technical74% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
74%
corporate business
53%
education learning
53%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
35162.159.45.149United States
AS13335CLOUDFLARENET
11104.26.0.111United States
AS13335CLOUDFLARENET
3172.66.44.126United States
AS13335CLOUDFLARENET
3104.26.1.111United States
AS13335CLOUDFLARENET
3141.101.121.124United States
AS13335CLOUDFLARENET
32606:4700:3009:aa59:4b67:100d:4f66:caf5United States
AS13335CLOUDFLARENET
32606:4700:20::ac43:44d8United States
AS13335CLOUDFLARENET
32606:4700:310c::ac42:2f82United States
AS13335CLOUDFLARENET
32606:4700:310c::ac42:2c7eUnited States
AS13335CLOUDFLARENET
32606:4700:20::681a:16fUnited States
AS13335CLOUDFLARENET
3810--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D882EEA1E8F1A633409790E16A721F4A7EE6EA03CA9B164033FC57C16F96DCACD1750D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:8Qch8E591uL9L8aUqHN7XyEgGXCZ68+0wbi:8QEl1094OpXyEg0Q+5i

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17800:gQiXoACzChEACDcKYlRksKMQgNHsALkk0IgGhAlNigYEUSAAgSIaCgQBBMjOehhI7ImEZAIFYAQTKGEFNhUiABBuELQoUSTB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Scan History

Scan history not available

Unable to load historical scan data