Security Scan Report: secure.beyondpay.com

Redirected to:
https://secure.beyondpay.com/ta/default.login
Submitted: Apr 18, 2026, 12:52:32 PMCompleted: Apr 18, 2026, 12:53:53 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 1 HTTP transaction. The main domain is secure.beyondpay.com and was registered NaN years ago.

Submitted URL: https://secure.beyondpay.com

Effective URL: https://secure.beyondpay.com/ta/default.loginRedirected

The Cisco Umbrella rank of the primary domain is #995,903 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 75%

5
Risk Score

The site hosts a credential‑collection form on a low‑ranked, old domain with heavily obfuscated JavaScript; while no direct malware indicators are present, caution is advised.

Risk Factors
Low Cisco Umbrella ranking for a domain that appears to claim a brand
Critical JavaScript obfuscation score despite lack of malware matches
Credential collection form on a domain with poor reputation
Safety Factors
Very old domain (over 26 years) indicating long‑standing registration
No malicious Indicators of Compromise found in threat intelligence databases
No JavaScript malware YARA signatures detected
No network‑level IDS alerts
Domain age information unavailable

Details

Page Title

Welcome back

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate business

(79%)

Domain Information

Domain 'secure.beyondpay.com' uses the commercial generic top-level domain (.com) with subdomain 'secure'. The second-level label 'beyondpay' is 9 characters long with three vowels and six consonants. Word splitting yields 2 words: beyond, pay. Average segment length settles at 4.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://secure.beyondpay.com

Page Load Overview

1.63s
Total Load Time
16
HTTP Requests
3
Domains
354 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:110 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business79% confidence
Type: webapp
Method: ml+structural

All Detected Categories

corporate business
79%
government public service
31%
news media journalism
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6142.251.140.170United States
AS15169Google LLC
535.227.252.254United States
AS396982Google LLC
535.186.241.17United States
AS396982Google LLC
163--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FCE19772D869DC33531398E4B4F5E71D24BAC22ECB0A8C40B7BC578D2BF2D458645AAD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:6m7sr69kGB0SbL4Dr54ZCnglRUbCUqsRM:ZK69kGaSnwF4ZCnwOTRM

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7366:rAJgAEABygGEBoR9wQQCTAQEUHAIAAEhQIQRCKmgoEITVAHASUhLFBkQAMCgkYQDEQamAIwhE14F5AGEFpQDCg0oOYIBVJgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffdfe7e7ffe7e7
Perceptual Hash:b399cc6666999926
Difference Hash:202a324d4d320c08
Wavelet Hash:fcfcfce400002424
Color Hash:#40bfb5

Other Hashes

Crop Resistant:202a324d4d320c08

Scan History

Scan history not available

Unable to load historical scan data