Security Scan Report: winterhaven.gov

Site favicon
Submitted: Oct 17, 2025, 8:35:02 AMCompleted: Oct 17, 2025, 8:35:52 AMpubliccompleted
Loading additional data...

Summary

This website contacted 25 IPs in 3 countries across 11 domains to perform 46 HTTP transactions. The main domain is winterhaven.gov and was registered NaN years ago.

Submitted URL: https://winterhaven.gov/

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

High‑risk site due to malicious IPs and new, unranked domain

Risk Factors
Malicious Indicators of Compromise (suspicious parking IPs) linked to the site
Very new domain (<90 days) increasing likelihood of abuse
Lack of Cisco Umbrella ranking, indicating low reputation
Domain age information unavailable

Details

Page Title

winterhaven.gov

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government

(95%)

Domain Information

You're looking at domain 'winterhaven.gov' on the United States government-restricted top-level domain (.gov) and has no subdomain. The second-level label 'winterhaven' is 11 characters long holding four vowels versus seven consonants. Splitting it apart reveals 2 words: winter, haven. Median word length is 5.5 characters. Most frequently, 'winter' shows up in English. You will also see it in Chinese (Pinyin) and Dutch contexts.

Screenshot

Security scan screenshot of https://winterhaven.gov/

Page Load Overview

25.05s
Total Load Time
46
HTTP Requests
11
Domains
87 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:19 chars
Detector Agreement:100%

Website Classification

Primary Category

government95% confidence
Type: dynamic
Method: structural

All Detected Categories

government
95%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
134.251.101.162Dublin, Leinster, Ireland
AS16509AMAZON-02
1188.114.96.3United States
AS13335CLOUDFLARENET
1208.91.196.46British Virgin Islands
AS40034CONFLUENCE-NETWORK-INC
1188.114.97.3United States
AS13335CLOUDFLARENET
1208.91.197.27British Virgin Islands
AS40034CONFLUENCE-NETWORK-INC
13.248.162.96Dublin, Leinster, Ireland
AS16509AMAZON-02
118.172.112.35United States
AS16509AMAZON-02
1199.191.50.135British Virgin Islands
AS40034CONFLUENCE-NETWORK-INC
154.75.69.192Dublin, Leinster, Ireland
AS16509AMAZON-02
118.172.112.37United States
AS16509AMAZON-02
4625--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A862E927B9933D14595B4166C6AB7789730E10C7FE078C18B98C1258EF4FB5A2393ABC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:3YoHSlF+hfCUA7Iual6QY2R4FoOHoT6rabwYoHsfO2/G:tSlF+nl6wIoOHoTzGsfzO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15342:I0GEsXHwQOKtMpEBIkQAESACgAqpEQFmDgQDoALQynBZhgEa6AARhQgQyAEAohCbFgUAClOQBk+mGHDD0IHECEkgAUSMEKpE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e7ffdb5a180000
Perceptual Hash:b4e4471b4b4e1a3b
Difference Hash:9696969692b2b208
Wavelet Hash:00ffffff5a181800
Color Hash:#e06cac

Other Hashes

Crop Resistant:9696969692b2b208

Scan History

Scan history not available

Unable to load historical scan data