Security Scan Report: har.ssffaa4.xyz

Redirected to:
https://2026-09-16.urldance.com/english?ssffaa4.xyz
Site favicon
Submitted: Sep 16, 2026, 2:47:34 AMCompleted: Sep 16, 2026, 2:49:31 AMpubliccompleted

This website contacted 7 IPs in 4 countries across 6 domains to perform 8 HTTP transactions. The main domain is 2026-09-16.urldance.com and was registered 26 years ago.

Submitted URL: https://har.ssffaa4.xyz

Effective URL:

https://2026-09-16.urldance.com/english?ssffaa4.xyz
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Fake 'verify password' resource gate on a host whose parent domain is reported by multiple feeds as the Vidar infostealer. Password harvesting plus obfuscated JS and cross-domain redirect: do not enter anything.

Risk Factors (5)
Multi-source threat-intel match naming the Vidar infostealer malware family on the page's own domain
Fake 'enter password to access' gate capturing a password with no username — credential harvesting pattern
Cross-domain redirect to unrelated dating/naming domain (urldance.com) with a date-based subdomain
Obfuscated JavaScript (eval + Function() constructor) unrelated to any visible page functionality
Third-party analytics/tracking endpoints (51.la, baidu, 72.chat) alongside the gate page
Domain age information unavailable

Details

Page Title

Resource Library - Premium Content, Secure Access

Scan Type

public

Domain Name Analysis

The domain 'har.ssffaa4.xyz' uses the open generic top-level domain (.xyz) and includes subdomain 'har'. The second-level label 'ssffaa4' is 7 characters long containing 2 vowels alongside four consonants; it also includes 1 digit. Breaking it apart gives 5 words: s, s, ffa, a, 4. Expect one character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://har.ssffaa4.xyz

Page Load Overview

90.30s
Total Load Time
44 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:x-default
Text Length:259 chars
Detector Agreement:100%
Language mismatch: Declared as x-default but detected as en

Website Classification

Primary Category

adult content45% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
45%
news media journalism
29%
documentation technical
29%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2156.225.108.42Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
154.215.31.113Aws · CLOUDSan Jose, California, United States
AS16509Amazon.com, Inc.
1156.225.108.41Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1156.225.108.43Hong Kong
AS139057Edgenext Legend Dynasty Pte. Ltd.
1125.74.108.43China
AS141998China Telecom
114.215.183.79China
AS4134Chinanet
143.159.107.113Singapore
87--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115912D3041F8153F949281C86A79E76ABAD1D84BDA5F4100B6FC6BA84F87EC2DC27258

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:CkbEpKm/dTu8xR8xR8xR8xsq5qXCEL5CdJrAYjlMJHbSdRdgn5Tn9sz5mXhJCCl/:CkMK+Fx5tFTBSLMEmV0D102u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4438:wAQAzAMAEAMAAwCACSIgBQAAgAJCBAACQBApoAAJFIoIQwAIIMZiAEkwARIYCBQJAAwgBAIVEoAJAJAHACAGACYAABNEQAII

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0019191b1f1f1f07
Perceptual Hash:88397326669d9973
Difference Hash:bfb3b3b3b3b3f3ff
Wavelet Hash:01191b1b1f1f1f1f
Color Hash:#4055bf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data