Security Scan Report: btbuu.com

Redirected to: https://btbuu.com/Login/index.html

Site favicon
Submitted: Dec 29, 2025, 11:46:47 PMCompleted: Dec 29, 2025, 11:47:55 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 21 HTTP transactions. The main domain is btbuu.com and was registered NaN years ago.

Submitted URL: https://btbuu.com/User/respwd

Effective URL: https://btbuu.com/Login/index.htmlRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam on a brand‑new domain; avoid and report.

Risk Factors
Newly registered domain (<7 days)
Credential harvesting login form
Social engineering detection by Google Safe Browsing
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

finance banking

(52%)

Domain Information

Within the commercial generic top-level domain (.com), 'btbuu.com' is registered while skipping any subdomain. Its registrable label 'btbuu' stretches across 5 characters holding 2 vowels versus 3 consonants. Word splitting yields two words: bt, buu. Median word length comes out to 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://btbuu.com/User/respwd

Page Load Overview

2.45s
Total Load Time
21
HTTP Requests
3
Domains
136 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
Text Length:316 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking52% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
52%
technology software
35%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7142.250.186.170United States
7206.119.180.146Los Angeles, California, United States
AS133199SonderCloud Limited
7104.16.174.226United States
AS13335CLOUDFLARENET
213--

Detected Technologies3

JQueryv1.10.2
100%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12582841093D45C3E701692C8DB6037AA74761757CA0A91007ABF2A75BF95EAB3C3B4CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:ofJiwYcAfo0fYQ0OoOJf0OJ2O1/SBYERPOaN3O4kBKYSdvYnrYr1ENTmJA+IFSNN:ofJHYcAfo0fYQZrF/SBYEJNpkBKYSdvB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:19107:AQgShAQQAFsCIIS0VXJUAACA2AhLMQhAsYAAiAAACbgEQAA4KCADTCJUEmaWCuTmAKHOajEBChITZAQJIQLyBGCq6aPmigAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1818181818000000
Perceptual Hash:c8d9636666666666
Difference Hash:33b2b2b2b2300020
Wavelet Hash:f93ebe3c7c584009
Color Hash:#9587c5

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data