Security Scan Report: nkdif.cfd

Submitted: Sep 20, 2026, 7:47:27 PMCompleted: Sep 20, 2026, 7:47:50 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Domain nkdif.cfd carries a multi-source 'unknown stealer' malware Indicator of Compromise on the page's own domain, combined with 68 eval() calls, encoded inline scripts and 4 cross-domain redirects to a cloaking gate. High risk — do not interact.

Risk Factors
Multi-source corroborated malware Indicator of Compromise (unknown stealer) on the primary domain
68 eval() calls plus inline encoding/decoding — obfuscated dynamic code execution
Four cross-domain redirects before a generic verification gate
Domain unranked in Cisco Umbrella with very low legitimacy score (10/100)
ML classifier labels the page phishing/scam
Domain age information unavailable

Details

Page Title

Verification Required

Scan Type

public

Domain Name Analysis

The domain name 'nkdif.cfd' uses the .cfd top-level domain with no subdomain. Count 5 characters in 'nkdif' with 1 vowel and 4 consonants. Tokenizing the label suggests 3 words: nk, d, if. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nkdif.cfd

Page Load Overview

3.54s
Total Load Time
1004 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:34 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing/scam40% confidence
Type: static
Method: structural

All Detected Categories

phishing/scam
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
244--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D4D1D8563AA71011E49391A53BBAC7493A64E213C64FC8A87FDC7118CF89FD59CA3B1C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:tIGk/xg86UwemeWYC0nrdy/cUyJ7HNLtTFnx/9g:tIPtLdFnx/C

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6218:cEJBSAAHwAAHEzHEAAhTIIRgIBBBaIAgkAXIAlBAnygQOEASkADTAoAUkAAItTAT4AqhCAhWgPiDg5AADoABJnZQiAEQosgI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffe7e7ffff
Perceptual Hash:b3cccc3399cc2633
Difference Hash:0000001008080000
Wavelet Hash:33331b1bc0c0fcfc
Color Hash:#2dd28d

Other Hashes

Crop Resistant:0000001008080000

Scan History

Scan history not available

Unable to load historical scan data