Security Scan Report: main.whoisxmlapi.com

Site favicon
Submitted: Dec 6, 2025, 11:52:36 AMCompleted: Dec 6, 2025, 11:54:41 AMpubliccompleted
Loading additional data...

Summary

This website contacted 158 IPs in 4 countries across 61 domains to perform 213 HTTP transactions. The main domain is main.whoisxmlapi.com and was registered NaN years ago.

Submitted URL: https://main.whoisxmlapi.com/

The Cisco Umbrella rank of the primary domain is #195,236 of the top 1 million websites

AI Security Verdict

AI analysis unavailable for this scan

Details

Page Title

WhoisXML API: #1 for Domain, WHOIS, IP, DNS & Threat Intelligence | WhoisXML API

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

suspicious phishing

(35%)

Domain Information

The domain name 'main.whoisxmlapi.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'main'. Count 11 characters in 'whoisxmlapi' containing four vowels alongside 7 consonants. It segments into four words: who, is, xml, api. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://main.whoisxmlapi.com/

Page Load Overview

2.43s
Total Load Time
213
HTTP Requests
61
Domains
1.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:58,850 chars
Detector Agreement:100%

Website Classification

Primary Category

suspicious phishing35% confidence
Type: webapp
Method: ml+structural

All Detected Categories

suspicious phishing
35%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
85172.67.73.122United States
AS13335CLOUDFLARENET
2034.120.156.210Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
16104.17.22.24United States
AS13335CLOUDFLARENET
14104.17.92.187United States
AS13335CLOUDFLARENET
6104.26.8.41United States
AS13335CLOUDFLARENET
6104.26.3.48United States
AS13335CLOUDFLARENET
5216.58.206.40United States
AS15169GOOGLE
5104.26.2.48United States
AS13335CLOUDFLARENET
4216.239.32.36United States
AS15169GOOGLE
3142.250.185.195United States
AS15169GOOGLE
213158--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14144DAB9C65014370AB344E8A1A1670EA653A325CED30544FAFDC3E4BBCED91DD329AD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:y738Bp6b9rG3ufoWuZEkuH1S6qpXEO8EOEM8XtVF76WG:jp6rG3ufoWuZEkiwnF76WG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:268322:AogoE4pURxFoUgRgiCWlEPCeqCyqAMgkKYuOD6KqqKIAHAcRwwCQYWTR5NiLRhECiQaADCBBjhQQESYQqI4i0KQAQBFSQCHh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff000000000003ff
Perceptual Hash:8a56bb0ad2a9d6a9
Difference Hash:6de5e7f5f5d5bb3a
Wavelet Hash:ff00311110387fff
Color Hash:#64d22d

Scan History

Scan history not available

Unable to load historical scan data