Security Scan Report: whats-xth.vip

Submitted: Oct 25, 2025, 8:06:19 AMCompleted: Oct 25, 2025, 8:07:38 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is whats-xth.vip and was registered NaN years ago.

Submitted URL: http://whats-xth.vip/

AI Security Verdict

Moderate Risk

Confidence: 78%

6
Risk Score

New domain with a circular redirect; no obvious malicious content but caution is advised.

Risk Factors
Circular redirect is a strong indicator of URL manipulation
Very new domain (<7 days) increases suspicion
Safety Factors
No malicious Indicators of Compromise matches found
No credential or payment forms present
Page displays a generic "Website not found" message
Domain age information unavailable

Details

Page Title

Sorry, the website has been stopped

Scan Type

public

Language

🇺🇸

English

(52% confidence)

Category

adult content

(27%)

Domain Information

The domain 'whats-xth.vip' uses the .vip top-level domain. Count 9 characters in 'whats-xth' holding 1 vowel versus seven consonants; it also includes 1 hyphen. Splitting it apart reveals 3 words: what, s, xth. The median word length lands at 3 characters. 'what' most often appears in Chinese (Pinyin). You may catch it in English and Czech as well.

Screenshot

Security scan screenshot of http://whats-xth.vip/

Page Load Overview

30.62s
Total Load Time
4
HTTP Requests
1
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:52%
Script Type:Latin
Text Length:129 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content27% confidence
Type: static
Method: ml+structural

All Detected Categories

adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
420.2.67.40Hong Kong, Hong Kong
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
41--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19943021803DE40A3CD9968D9426B3F3C842A5873DA1C98BD1F5B6DB4CA0D8A47A7F1E5

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:FHJYDDQHVZHIs91TXESJBjgBSp00yCqJ3Z+IYM3WiesRQiULO0bpD9tcNQEfdomi:lmDD6oeFUycwpk06hWp1b99c7VE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:58253:EUiMaVDSkYS0xkQBgAkJSACzQIEOFMICYgADRgmqEAc4cMJYSg0AOpCEVUQVAwAAYQDCQ8gDQFAQFNNopDOJaYVIypATErIC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7e7e7ffffffff
Perceptual Hash:e6668c99993333c6
Difference Hash:00080c0c00000000
Wavelet Hash:ffe7e7c300000000
Color Hash:#9479d2

Other Hashes

Crop Resistant:00080c0c00000000

Scan History

Scan history not available

Unable to load historical scan data