Security Scan Report: tinyurl.com

Redirected to: https://ixz.rlj.mybluehost.me/ol282f645de/auth/dV9oBz/login.php?id=34817360

Site favicon
Submitted: Nov 3, 2025, 2:27:26 AMCompleted: Nov 3, 2025, 2:28:36 AMpubliccompleted
Loading additional data...

Summary

This website contacted 25 IPs in 2 countries across 7 domains to perform 24 HTTP transactions. The main domain is ixz.rlj.mybluehost.me.

Submitted URL: https://tinyurl.com/4uemtus2

Effective URL: https://ixz.rlj.mybluehost.me/ol282f645de/auth/dV9oBz/login.php?id=34817360Redirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Phishing site impersonating Netflix on a newly created, unranked domain.

Risk Factors
Brand impersonation on an unranked, newly registered domain
Multiple redirects (4) increasing suspicion
Use of a generic URL shortener (tinyurl.com) to hide final destination
Hosting on a generic MyBluehost subdomain
Absence of any legitimate Netflix domain in the redirect chain
Domain age information unavailable

Details

Page Title

Netflix

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

entertainment media

(83%)

Domain Information

Within the commercial generic top-level domain (.com), 'tinyurl.com' is registered while skipping any subdomain. The registrable portion 'tinyurl' spans 7 characters split between two vowels and five consonants. Breaking it apart gives 1 word: tinyurl. The median word length lands at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tinyurl.com/4uemtus2

Page Load Overview

36.86s
Total Load Time
24
HTTP Requests
7
Domains
932 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
Text Length:369 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media83% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
83%
social media network
46%
corporate business
35%
social_media
25%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
24142.250.181.234United States
AS15169GOOGLE
050.6.34.21Frankfurt am Main, Hesse, Germany
AS31898ORACLE-BMC-31898
0104.17.112.233United States
AS13335CLOUDFLARENET
0151.101.2.137San Francisco, California, United States
AS54113FASTLY
0104.16.175.226United States
AS13335CLOUDFLARENET
0104.17.24.14United States
AS13335CLOUDFLARENET
0104.16.174.226United States
AS13335CLOUDFLARENET
0142.250.184.227United States
AS15169GOOGLE
02a04:4e42:600::649United States
AS54113FASTLY
0151.101.130.137San Francisco, California, United States
AS54113FASTLY
2425--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17BC231DB549262658D135E6343CC092C9D399EA349121E9EB22E190D9FC7FF8279333B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:dMCMPMCMfMCM8MCMGMCM/MCMtMCMAspuolIHabzu8o7P:dMCMPMCMfMCM8MCMGMCM/MCMtMCMAsp4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:25964:ABcIDYFCJOxAjQERQFVQVMIAIQBtSzPMEHNCERVFgytBiFMokiDAQCgZgAwCDEIgKVjAh6EqoTQmAagAgUgZwBoB4oISgLCA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bf711b9b44f19100
Perceptual Hash:aa855fe232bca915
Difference Hash:67c5f6378dc925cd
Wavelet Hash:bf711f1fc5f18100
Color Hash:#d2bf2d

Other Hashes

Crop Resistant:67c5f6378dc925cc

Scan History

Scan history not available

Unable to load historical scan data