Security Scan Report: stealer.best

Submitted: Aug 26, 2026, 3:24:12 PMCompleted: Aug 26, 2026, 3:25:38 PMpubliccompleted

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is stealer.best and was registered 2 months ago.

Submitted URL: https://stealer.best

AI Security Verdict

High Risk

Confidence: 88%

7
Risk Score

The site is flagged as high‑risk due to a confirmed malware indicator on its primary domain despite lacking forms or impersonation.

Risk Factors
Primary domain malware indicator
New domain age
Unranked / low reputation
Domain age information unavailable

Details

Page Title

stealer.best | 522: Connection timed out

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(68%)

Domain Information

Domain 'stealer.best' uses the .best top-level domain and has no subdomain. The registrable portion 'stealer' spans 7 characters holding three vowels versus 4 consonants. Splitting it apart reveals 1 word: stealer. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://stealer.best

Page Load Overview

20.05s
Total Load Time
8
HTTP Requests
1
Domains
12 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:934 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical68% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
68%
technology software
60%
government public service
49%
cryptocurrency blockchain
42%
news media journalism
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8172.67.199.195Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
81--

Page Statistics

8
Requests
1
Unique Domains
16.2 KB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T138E17575B1F51276006381923695FB6A7AE0C613CBFF449473DDC2732FAEE82A943294

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:lZDa/D2KUlfG4Fh8/G4FU+fo424FN+skKm/jotQmHB+dWSYnRC3/NaQxx:lha/CdevHVyjoWQ+DYnM3gex

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6944:wCQBGAgACWODTQC8igwD4wJDFhFFoVBlkESECIhjSRBADQQgkQhBRQkYrIoAAEEVIBQB8RQEAoDLZzAQCBDFBpgAYDUZBMUs

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c60000d7f7f3ff
Perceptual Hash:f439e4b49a673164
Difference Hash:1e3e8e8a34160606
Wavelet Hash:c70e0000d6c7f3ff
Color Hash:#40bf4f

Other Hashes

Crop Resistant:1e3e8e8a34160606

Scan History

Scan history not available

Unable to load historical scan data