Security Scan Report: trk.inboxclicks.biz

Redirected to:
https://www.google.com/?sub1=59544ee7f2dee70159c18f9fd02f741464eb8e1f5...
Site favicon
Submitted: Oct 4, 2026, 7:35:51 PMCompleted: Oct 4, 2026, 7:36:25 PMpubliccompleted

This website contacted 11 IPs in 1 country across 6 domains to perform 40 HTTP transactions. The main domain is google.com and was registered 18 years ago.

Submitted URL: https://trk.inboxclicks.biz/E0ft_ySMouXlpjV061hNmozC4MI5Q9UmMU-JJ7hFDvdRyvOTmHeHRWvlfjI672gm8lQ8HI6Du8E_dg8MVtKas6YHBw1UC-LOvIxrM2rjS0lUDlqyABdHzQvs2-KDTCQP0yzezGOa79ubp6nd0jM091joQUHwNFEFl24rX9izqXLCfEMwR5FqCe8iMK0CujuLqsEG5Ir1_G188BrxuQuWHn6dbUQBzGRy9KxGLYmTA9HJ-y3EM1bSLmvlW1KNFMBdDzOh

Effective URL:

https://www.google.com/?sub1=59544ee7f2dee70159c18f9fd02f741464eb8e1f5...
Redirected

AI Security Verdict

Moderate Risk

Confidence: 55%

3
Risk Score

Opaque .biz click-tracking redirect ending on google.com, gated behind a bot-protection 'Human Verification' interstitial. No forms, credentials, malware or threat-intel hits — suspicious traffic routing, not proven phishing.

Risk Factors (3)
Opaque tracking/redirect gateway on a .biz domain that forwards to a third-party site with affiliate-style sub parameters
Content served differs between datacenter scanner and residential client (bot-protection/cloaking pattern)
The verification bare 'proof-of-work' page is not standard Google interstitial content, so the redirect destination's rendering is unverified
Safety Factors (4)
No credential, password or payment form on the page — nothing harvested
No Indicators of Compromise, no JavaScript malware (YARA), no known malicious kit roster match
No credential exfiltration and no cross-origin JS network targets observed
Destination resolves to the genuine google.com domain with legitimate Google static/play resources (gstatic.com, play.google.com, clients6.google.com)
Domain age information unavailable

Details

Page Title

Verification

Scan Type

public

Domain Name Analysis

You're looking at domain 'trk.inboxclicks.biz' on the business-focused generic top-level domain (.biz), featuring subdomain 'trk'. The second-level label 'inboxclicks' is 11 characters long split between three vowels and eight consonants. Splitting it apart reveals 3 words: in, box, clicks. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://trk.inboxclicks.biz/E0ft_ySMouXlpjV061hNmozC4MI5Q9UmMU-JJ7hFDvdRyvOTmHeHRWvlfjI672gm8lQ8HI6Du8E_dg8MVtKas6YHBw1UC-LOvIxrM2rjS0lUDlqyABdHzQvs2-KDTCQP0yzezGOa79ubp6nd0jM091joQUHwNFEFl24rX9izqXLCfEMwR5FqCe8iMK0CujuLqsEG5Ir1_G188BrxuQuWHn6dbUQBzGRy9KxGLYmTA9HJ-y3EM1bSLmvlW1KNFMBdDzOh

Page Load Overview

1.99s
Total Load Time
989 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:161 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical54% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
54%
government public service
53%
healthcare medical
53%
adult content
50%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1051.81.201.215Hillsboro, Oregon, United States
AS16276OVH SAS
3142.251.152.119Google · CDNUnited States
AS15169Google LLC
3142.251.154.119Google · CDNUnited States
AS15169Google LLC
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
3142.251.150.119Google · CDNUnited States
AS15169Google LLC
3142.251.153.119Google · CDNUnited States
AS15169Google LLC
3142.251.151.119Google · CDNUnited States
AS15169Google LLC
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
3142.251.156.119Google · CDNUnited States
AS15169Google LLC
3142.251.157.119Google · CDNUnited States
AS15169Google LLC
4011--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18251E9727599003A7EAEF2B5A190B39CF1818702A6537BF058D8A0A5C4CDBC629737D8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:6uedvOWjQj1m8nXe6T+Cb9kM5E+GeprpFgh:63NOWjrcCd+DprpFgh

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3144:AwQCQAAAAIIIEEGUAAAgBIFABQFIIIIACoAABZAkNIAQAAEAAEAQAIZEAQQYQAhAAACACBAoEARIFgAAIGAEEQCGKAEAAQAC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7ffffe7e7ffff
Perceptual Hash:b388cc67939966cc
Difference Hash:0008322a28281008
Wavelet Hash:c3c3dbc31b030f0f
Color Hash:#e0856c

Other Hashes

Crop Resistant:0008322a28281008

Scan History

Scan history not available

Unable to load historical scan data