Security Scan Report: zbzd-56945.portmap.host

Redirected to:
https://portmap.io/
Submitted: Sep 16, 2026, 5:47:53 AMCompleted: Sep 16, 2026, 5:48:38 AMpubliccompleted

This website contacted 36 IPs in 3 countries across 22 domains to perform 93 HTTP transactions. The main domain is portmap.io and was registered 22 years ago.

Submitted URL: https://zbzd-56945.portmap.host

Effective URL:

https://portmap.io/
Redirected

AI Security Verdict

High Risk

Confidence: 62%

7
Risk Score

Legitimate self-branded Portmap.io port-forwarding site; no forms or credential collection. Threat-intel hits are generic tunneling/abuse-reputation tags plus a single unverified, third-party XWorm indicator — dual-use service warrants caution, not a scam verdict.

Risk Factors
Service is a port-forwarding/tunneling tool that is frequently abused to expose malware C2 and remote access — inherently dual-use
Entry hostname zbzd-56945.portmap.host carries a single-source XWorm community submission (unverified)
Six eval() calls present (dynamic code execution) — common in legitimate analytic/consent scripts but noted
Domain age information unavailable

Details

Page Title

Portmap.io - free port forwarding solution

Scan Type

public

Domain Name Analysis

The domain 'zbzd-56945.portmap.host' uses the .host top-level domain with subdomain 'zbzd-56945'. The second-level label 'portmap' is 7 characters long holding 2 vowels versus 5 consonants. Tokenizing the label suggests 2 words: port, map. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zbzd-56945.portmap.host

Page Load Overview

5.32s
Total Load Time
3.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:7,815 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software36% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
36%

Detected Features

Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
23142.251.110.157Google · CDNUnited States
AS15169Google LLC
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2193.161.193.99Russia
AS198134Ooo Getwifi
2104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
223.36.162.212Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2172.67.75.33Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.150.119Google · CDNUnited States
AS15169Google LLC
2104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2192.178.183.157Google · CDNUnited States
AS15169Google LLC
9336--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F36144074D968E0422212902F8927045CDF6770F9528A8F1F95D427E3FD4BAAD077E6E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nfqdBXGPIEBBZi3/bKbNbZ3ErVCrE1ne1rVfrqZNZ89ZtyZHwAF8zRSYSr/u+CIt:nmAd5ZzDBfXwwFIJj1t

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3406:AlCAAACAAEAKAAhAFAAAAAAEFEkAACEIAAEQJAMDQCEQMBAAAFCEBA0ECKAAJgAxAAAWECKMAACggAEAACOCBAARACAAAgAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:d3003c3c3cc7ffff
Perceptual Hash:8a0af4e48f87a5cb
Difference Hash:a7b1696969961621
Wavelet Hash:00003c3c3cc3ffff
Color Hash:#bf4a40

Scan History

Scan history not available

Unable to load historical scan data