Security Scan Report: btq9.top

Redirected to: https://btq9.top/

Submitted: Oct 21, 2025, 11:40:14 AMCompleted: Oct 21, 2025, 11:44:00 AMpubliccompleted
Loading additional data...

Summary

This website contacted 42 IPs in 4 countries across 4 domains to perform 72 HTTP transactions. The main domain is btq9.top and was registered NaN years ago.

Submitted URL: http://btq9.top/

Effective URL: https://btq9.top/Redirected

AI Security Verdict

High Risk

Confidence: 85%

10
Risk Score

High‑risk phishing site using URL manipulation on a brand‑new unranked domain.

Risk Factors
URL manipulation (spoofed URL using history.pushState/replaceState)
Very new domain (<30 days) with no established reputation
Unranked domain in Cisco Umbrella
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇺🇸

English

(70% confidence)

Category

e-commerce

(58%)

Domain Information

The domain name 'btq9.top' uses the .top top-level domain. The core label 'btq9' covers 4 characters containing 0 vowels alongside three consonants, notching 1 digit. Segmentation suggests 3 words: bt, q, 9. Median word length comes out to one character. Most frequently, 'bt' shows up in Danish. It also appears in English and Indonesian contexts.

Screenshot

Security scan screenshot of http://btq9.top/

Page Load Overview

18.97s
Total Load Time
72
HTTP Requests
4
Domains
859 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:70%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:70%
Script Type:Latin
HTML Lang Attribute:en
Text Length:653 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce58% confidence
Type: static
Method: ml+structural

All Detected Categories

e-commerce
58%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3652.219.162.21Tokyo, Tokyo, Japan
AS16509AMAZON-02
313.5.158.103Tokyo, Tokyo, Japan
AS16509AMAZON-02
29104.21.85.154United States
AS13335CLOUDFLARENET
3142.250.181.234United States
AS15169GOOGLE
152.219.17.17Tokyo, Tokyo, Japan
AS16509AMAZON-02
13.5.155.167Tokyo, Tokyo, Japan
AS16509AMAZON-02
1172.67.207.80United States
AS13335CLOUDFLARENET
13.5.156.87Tokyo, Tokyo, Japan
AS16509AMAZON-02
13.5.158.254Tokyo, Tokyo, Japan
AS16509AMAZON-02
1124.222.174.117Shanghai, Shanghai, China
AS45090Shenzhen Tencent Computer Systems Company Limited
7242--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C3432E3872433863057BA8E0B0D45F08B2A29B3AC2154654F7FD236A77DACE16F563E5

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Um8DSqmfV/8DSqmfuSJBQSJRQhBsUQMfyMh+YoxtK8eeDmLarmZ5Lf+RLfPCLfsf:78S80xfb

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:60183:JjMDAVpFQEAIHuSgBYCBMpBCDIDxEzDUHGGAAo9QCinQHWKwAAAToBQAhkQUaGBiAXABHpDS5kVOBIORi8GAEDjAQBtYA3ek

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data