Security Scan Report: sel.ssffaa4.xyz

Redirected to:
https://2026-09-13.urldance.com/english?ssffaa4.xyz
Site favicon
Submitted: Sep 13, 2026, 3:47:55 AMCompleted: Sep 13, 2026, 3:48:59 AMpubliccompleted

This website contacted 8 IPs in 4 countries across 6 domains to perform 10 HTTP transactions. The main domain is 2026-09-13.urldance.com and was registered 3 months ago.

Submitted URL: https://sel.ssffaa4.xyz

Effective URL:

https://2026-09-13.urldance.com/english?ssffaa4.xyz
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Password-gated 'Resource Hub' on a domain flagged by multiple feeds as Vidar stealer malware, with eval/Function code generation and a cross-domain redirect. Do not enter any password; avoid.

Risk Factors (6)
Content-malware Indicators of Compromise on the scanned domain itself (Vidar stealer family)
Multi-source corroborated malware reputation for ssffaa4.xyz
Password field without any username/email field
Dynamic code execution (eval/Function) on a trivial password-gate page
Cross-domain redirect to an unrelated 'urldance.com' host
Entry domain has no Cisco Umbrella ranking despite claimed content hub
Domain age information unavailable

Details

Page Title

Resource Library - Premium Content, Secure Access

Scan Type

public

Domain Name Analysis

Within the open generic top-level domain (.xyz), 'sel.ssffaa4.xyz' is registered with subdomain 'sel'. Its registrable label 'ssffaa4' stretches across 7 characters containing two vowels alongside 4 consonants, along with one digit. Segmentation suggests 5 words: s, s, ffa, a, 4. Average segment length settles at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sel.ssffaa4.xyz

Page Load Overview

10.07s
Total Load Time
58 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:x-default
Text Length:261 chars
Detector Agreement:100%
Language mismatch: Declared as x-default but detected as en

Website Classification

Primary Category

adult content50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
50%
government public service
36%
news media journalism
34%
documentation technical
34%
cryptocurrency blockchain
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3156.225.108.42Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1156.225.108.41United States
AS4134Chinanet
154.215.31.113Aws · CLOUDSan Jose, California, United States
AS16509Amazon.com, Inc.
143.159.107.113Singapore
1156.225.108.43Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1183.240.98.228China
AS56040China Mobile communications corporation
114.215.182.140China
AS4134Chinanet
1218.60.100.155China
AS4837CHINA UNICOM China169 Backbone
108--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T193912D3041F8653F949281C96A79E76FBAD1D84BDA1F4100B6FC6BA44F87EC2DC27258

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:CkbEpKm/dTu8xR8xR8xR8xsq5qXCEL5CdJrAYjlMJHbSdRZn5Tn9sz5mXiCvRlok:CkMK+Fx5tFTBSL7EmZRmf102u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4440:wCQAxAMAEAgBAACGCSIgDQCCgAJBQAACQBApAAADFIoIQwAIIEBiAgEiIQIYABQJEAwgBAIRkoBJQIACACAAACQgLBNEQFII

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0019191b1f1f1f07
Perceptual Hash:88397366669d9933
Difference Hash:9fb3b3b3b3b3f3ff
Wavelet Hash:01191b1b1f1f1f1f
Color Hash:#ac6e53

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data