Security Scan Report: saojosedogoiabal.mg.gov.br

Submitted: Oct 31, 2025, 6:38:23 PMCompleted: Oct 31, 2025, 6:39:35 PMpubliccompleted
Loading additional data...

Summary

This website contacted 30 IPs in 5 countries across 9 domains to perform 11 HTTP transactions. The main domain is saojosedogoiabal.mg.gov.br and was registered NaN years ago.

Submitted URL: https://saojosedogoiabal.mg.gov.br/dhuch/box3Drenewal.php

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing site impersonating DHL; do not enter credentials.

Risk Factors
Brand impersonation of DHL on a government subdomain (saojosedogoiabal.mg.gov.br)
Credential harvesting form (username and password fields)
Hidden password field indicating attempt to obscure input
Domain age information unavailable

Details

Page Title

Tracking made easy... | DHL

Scan Type

public

Language

🇺🇸

English

(69% confidence)

Category

government

(48%)

Domain Information

The domain 'saojosedogoiabal.mg.gov.br' uses the Brazilian country-code top-level domain (.mg.gov.br) with no subdomain. Its registrable label 'saojosedogoiabal' stretches across 16 characters with 9 vowels and seven consonants. Splitting it apart reveals 6 words: sao, jose, do, goi, a, bal. The median word length lands at 3 characters. 'sao' most often appears in Hungarian. Usage also turns up in Portuguese and Galician contexts.

Screenshot

Security scan screenshot of https://saojosedogoiabal.mg.gov.br/dhuch/box3Drenewal.php

Page Load Overview

22.47s
Total Load Time
11
HTTP Requests
9
Domains
24 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:69%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:69%
Script Type:Latin
Text Length:293 chars
Detector Agreement:100%

Website Classification

Primary Category

government48% confidence
Type: static
Method: ml+structural

All Detected Categories

government
48%
documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11163.181.92.201Frankfurt am Main, Hesse, Germany
AS24429Zhejiang Taobao Network Co.,Ltd
02.19.225.87Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
0142.250.185.195United States
AS15169GOOGLE
0192.185.131.43United States
AS19871NETWORK-SOLUTIONS-HOSTING
087.248.119.251United Kingdom
AS203220Yahoo-UK Limited
0111.124.203.38China
AS139203Guizhou GuiAn IDC
0150.171.28.10United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
0184.30.209.111Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
0240e:938:a07:6:0:14:203:38China
AS139203Guizhou GuiAn IDC
02a02:26f0:3500:299::4b3fFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
1130--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A391745A77482C3ADC0786A7F112BFCE8E80E0AB12219658FCBD71CAA4D046D65793CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:RUdQU5sbNddddVbsPqdd8ddddddddddddddddddddybKPqddGO6bXdddddddde3j:Ra5sIOuO3xxQaMWV

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4475:ICAAAAoAmQAAEAMhwACAAAIACBACAABMgABKAQOCQwEBEgYAACKlAghEgUgkEeGQ0koJVQQgEEJAAIAEATIBACGEUgAAIyEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data