Security Scan Report: glot.io

Redirected to:
https://glot.io/snippets/hfd3x9ueu5
Site favicon
Submitted: Sep 13, 2026, 7:48:07 PMCompleted: Sep 13, 2026, 7:49:11 PMpubliccompleted

This website contacted 6 IPs in 4 countries across 4 domains to perform 17 HTTP transactions. The main domain is glot.io and was registered 16 years ago.

Submitted URL: http://glot.io/snippets/hfd3x9ueu5

Effective URL:

https://glot.io/snippets/hfd3x9ueu5
Redirected

AI Security Verdict

Moderate Risk

Confidence: 70%

5
Risk Score

Established code-sharing site with self-branding and no forms, but this snippet hosts an obfuscated base64 curl|bash downloader from a raw IP disguised as an installer. Do not copy or run it.

Risk Factors
Malicious copy-paste payload: base64-obfuscated curl | bash downloader pointing at a raw IP address
Disguised as a legitimate 'Installer-Package' to trick users into running it
Snippet is presented for copy-paste execution, which would hand remote code execution to a hostile server
Safety Factors
Host domain glot.io is 14 years old and well established
Self-branding only — page presents its own service, no brand impersonation
No password, disguised-password, or payment fields anywhere on the page
No JavaScript malware signatures, no credential exfiltration, no cross-origin credential forms
No Google Safe Browsing or IDS phishing/malware alerts
Domain age information unavailable

Details

Page Title

openclawcli – Bash snippet | glot.io

Scan Type

public

Domain Name Analysis

Domain 'glot.io' uses the British Indian Ocean Territory country-code top-level domain (.io) without a subdomain. The registrable portion 'glot' spans 4 characters split between one vowel and three consonants. Splitting it apart reveals 2 words: g, lot. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://glot.io/snippets/hfd3x9ueu5

Page Load Overview

2.57s
Total Load Time
255 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,224 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software44% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
44%
government public service
25%

Detected Features

Search
OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2159.65.211.77Slough, England, United Kingdom
AS14061DigitalOcean, LLC
2141.94.2.147France
AS16276OVH SAS
2152.42.150.143Amsterdam, North Holland, Netherlands
AS14061DigitalOcean, LLC
299.84.152.70Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
176--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19A6245F2F4046F3B121348CAEA671BB970A6CA56D5162C44D7F85FE90FE3C90EA17066

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:afSWve/A8J+oraiVE2/Cn1V5IDt4mTR7IwgVU2tf8DJhgSpHevqmhiG:bWmY81+iVE6cWhRRAU2tOcqmkG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:14588:0EGkFk6BssEkiosh2DCRU6DiG1AyAyUABACgYRxAMLwQgxkhREGYgiBv7ilRgAUBUQAiBelwPCADSSycAmQCSQUeQYBlKqdJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fc04ffffffff0100
Perceptual Hash:cada6a32d525d525
Difference Hash:89098688808c4763
Wavelet Hash:0000ffffff0600fc
Color Hash:#d279a3

Scan History

Scan history not available

Unable to load historical scan data