Security Scan Report: butler-johnson.com

Site favicon
Submitted: Aug 17, 2026, 12:24:20 PMCompleted: Aug 17, 2026, 12:25:27 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

The site impersonates Facebook and harvests login credentials; treat as confirmed phishing scam.

Risk Factors (4)
Brand impersonation of Facebook on unrelated domain
Unranked domain with recent registration
Credential collection form (email/phone and password)
Cross‑origin network requests (though not malicious alone)
Domain age information unavailable

Details

Page Title

Facebook – Logga in eller registrera dig

Scan Type

public

Domain Name Analysis

The domain 'butler-johnson.com' uses the commercial generic top-level domain (.com) without a subdomain. The second-level label 'butler-johnson' is 14 characters long with four vowels and nine consonants, notching one hyphen. Splitting it apart reveals 2 words: butler, johnson. Expect 6.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://butler-johnson.com/login-check.html

Page Load Overview

0.81s
Total Load Time
40 KB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:sv
Text Length:266 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network100% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
100%
phishing scam
51%
news media journalism
45%
government public service
43%
adult content
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2188.114.96.3Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1157.240.0.35Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
1184.24.77.66Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
1157.240.0.37Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
54--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C132969B297704116A17E5A97BA7071A3625C007D44BC8583FEC5388CFDBE899AF378C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:rDXkV81K5M0R6xaYGFaX2qioTy8yav+/IflYV+PLRqc2vaHA8UB/3TFiGaIiz2G7:rDXkb4qWFr5kukO9v9GLYB+nm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11501:DkmIAABSWwpiDBAQZYoUItgQM3gwhQmkj1AkAFiIRkUTDFkpAkJ3gwgBE5SAxACQ5qBmASILIwmQEAkA+KYQxjwgMEoUGVCg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffe7
Perceptual Hash:b399cc6633998c66
Difference Hash:0800000c4d00080c
Wavelet Hash:e4fcfce4243c2424
Color Hash:#6ca2e0

Other Hashes

Crop Resistant:0800000c4d00080c

Scan History

Scan history not available

Unable to load historical scan data