Security Scan Report: dizyo.ir

Redirected to:
blob:https://dizyo.ir/ac4b2490-7303-455b-a0f5-22fff37e9dfd
Submitted: Sep 17, 2026, 8:25:19 PMCompleted: Sep 17, 2026, 8:25:42 PMpubliccompleted

This website contacted 11 IPs in 4 countries across 9 domains to perform 44 HTTP transactions. The main domain is and was registered 6 years ago.

Submitted URL: https://dizyo.ir/images/re.html

Effective URL:

blob:https://dizyo.ir/ac4b2490-7303-455b-a0f5-22fff37e9dfd
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed Wells Fargo phishing kit on dizyo.ir: fake login plus SSN, ATM PIN and card/CVV capture, exfiltrating credentials cross-origin to far-well.pages.dev. Do not enter any data.

Risk Factors (5)
Impersonation of Wells Fargo on a non-Wells Fargo domain (dizyo.ir)
Cross-origin exfiltration of credentials and payment data to far-well.pages.dev
Collection of full identity and financial data (SSN, ATM PIN, card/CVV, DOB, mother's maiden name)
Disguised password field and unicode evasion technique
Payment card capture form on an unrelated host
Domain age information unavailable

Details

Page Title

Sign On to View Your Personal Accounts | Wells Fargo

Scan Type

public

Domain Name Analysis

Domain 'dizyo.ir' uses the Iranian country-code top-level domain (.ir). The registrable portion 'dizyo' spans 5 characters split between 2 vowels and 3 consonants. Breaking it apart gives two words: dizy, o. Median word length is 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dizyo.ir/images/re.html

Page Load Overview

1.60s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,562 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking36% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
36%
e-commerce
25%
social_media
25%

Detected Features

Login Form
Search
Payment

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
494.139.166.159Iran
AS206065Tose'h Fanavari Ertebabat Pasargad Arian Co. PJS
4151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
4172.66.44.108Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.66.47.148Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.217.117.4Google · CDNUnited States
AS15169Google LLC
495.101.75.50Akamai · CDNVienna, Vienna, Austria
AS20940Akamai International B.V.
495.101.243.165Akamai · CDNManchester, England, United Kingdom
AS16625Akamai Technologies, Inc.
4142.251.127.148Google · CDNUnited States
AS15169Google LLC
4142.251.127.149Google · CDNUnited States
AS15169Google LLC
4411--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17B24E811D3C88CF59223CFD8A45E5A063690D539C5869CD1F9EC82993FFBD48AD2E2D8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:WYN18X9WdeAmFxvvu062avue3vua2qvuT3vuyvuNs2UvuTSvuhU2H/2x02hvum8M:p18t2DqHWVFBofw/Ty8tsQHWFTt34q

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:223189:UDEQaWBeN4sEriygVCI6rwA5WAAAlTQoJagBjgyCiDK4+gAUTFwEGGAFMEnDBBoWSYgQiMiAHKBQIMLBuWYSDVxJQKkEdFoA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c3f3f3939ffff
Perceptual Hash:8b02746974777c69
Difference Hash:fde9e9e9e3736bfa
Wavelet Hash:003c3c3d39397b1f
Color Hash:#5f3a78

Scan History

Scan history not available

Unable to load historical scan data