Security Scan Report: tili.sanoma.fi

Redirected to:
https://oma.sanoma.fi/
Site favicon
Submitted: Sep 17, 2026, 6:37:19 PMCompleted: Sep 17, 2026, 6:38:04 PMpubliccompleted

This website contacted 23 IPs in 4 countries across 10 domains to perform 218 HTTP transactions. The main domain is oma.sanoma.fi and was registered 8 years ago.

Submitted URL: https://tili.sanoma.fi

Effective URL:

https://oma.sanoma.fi/
Redirected

The Cisco Umbrella rank of the primary domain is #486,065 of the top 1 million websites

AI Security Verdict

Safe Website

Confidence: 93%

1
Risk Score

Legitimate Sanoma customer-support portal on its own long-established domain. No credential/payment forms, no impersonation, no malware. Only a generic third-party IP reputation tag, which is not content evidence.

Safety Factors (5)
35-year-old established domain owned by Sanoma Media Finland Oy
Page content and branding are the site's own (self-branding matches domain)
No credential-harvesting or payment form present
No YARA malware patterns, no IDS alerts, no malicious JavaScript behavior
No cross-origin credential exfiltration detected
Domain age information unavailable

Details

Page Title

Oma Sanoma | Sanoman asiakastuki

Scan Type

public

Domain Name Analysis

You're looking at domain 'tili.sanoma.fi' on the Finnish country-code top-level domain (.fi); it also runs on subdomain 'tili'. The second-level label 'sanoma' is 6 characters long holding 3 vowels versus 3 consonants. Word splitting yields three words: s, a, noma. Median word length is 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tili.sanoma.fi

Page Load Overview

8.05s
Total Load Time
3.7 MB
Total Size

Language Analysis

Primary Language

🇫🇮Finnish
Code: fi
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fi-FI
Text Length:1,842 chars
Detector Agreement:75%

Website Classification

Primary Category

news media journalism97% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

news media journalism
97%
e-commerce shopping
94%
healthcare medical
91%
blog personal website
87%
government public service
68%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
203.174.46.6Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
918.245.86.36Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
918.245.86.21Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
93.174.46.102Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
93.174.46.69Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
93.174.46.28Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
923.49.70.64Palermo, Sicily, Italy
AS6762TELECOM ITALIA SPARKLE S.p.A.
9185.111.111.155Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
918.245.60.87Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
9192.178.183.97Google · CDNUnited States
AS15169Google LLC
21823--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15B615B2238A0D41657254B45BDC2BC3CED82F65F858998B0E1A721FDCBA0BE34B6741F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:vr3es7NLnN0jN9NbrNQNLZlNKeNgN0+kwoHgWf7QKffTM7eN:Cm0QZ62+kNHgyQKf47eN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3219:AAwAAAABgDBAAQAABAAgAUISAAsAYAAQAgFQBAAACYABioiCgKIggoAAAk0IABCAjMEADQAgEAEQAAAAAgABgBIAIAgAQAKA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c3c3c3c3c3c00
Perceptual Hash:9b6e65332c191b66
Difference Hash:1669697969696986
Wavelet Hash:00bdbdbdbd3c3c00
Color Hash:#6cbf40

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data