Security Scan Report: xcat2026.com

Redirected to:
https://xcat2026.com/auth/login?callback=%2Fuser%2Fticket
Site favicon
Submitted: Sep 12, 2026, 10:42:02 AMCompleted: Sep 12, 2026, 10:42:23 AMpubliccompleted

This website contacted 7 IPs in 4 countries across 6 domains to perform 26 HTTP transactions. The main domain is xcat2026.com and was registered 10 years ago.

Submitted URL: https://xcat2026.com/user/ticket

Effective URL:

https://xcat2026.com/auth/login?callback=%2Fuser%2Fticket
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Page impersonates Telegram, collects login credentials on a 3‑day‑old unranked domain – confirmed phishing scam.

Risk Factors (4)
Brand impersonation (Telegram) on unrelated domain
Newly registered domain (<7 days)
Credential harvesting form
Unranked domain in Cisco Umbrella
Domain age information unavailable

Details

Page Title

喵了个咪 · XCAT · 学习助理 | Secured Private Networks

Scan Type

public

Domain Name Analysis

The domain name 'xcat2026.com' uses the commercial generic top-level domain (.com) without a subdomain. Its registrable label 'xcat2026' stretches across 8 characters holding one vowel versus three consonants, plus four digits. Word splitting yields 3 words: xc, at, 2026. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://xcat2026.com/user/ticket

Page Load Overview

3.43s
Total Load Time
786 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-cn
Text Length:307 chars
Detector Agreement:67%

Website Classification

Primary Category

social media network73% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
73%
education learning
53%
technology software
33%
adult content
25%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8185.111.111.154Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.17.5.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3149.154.167.99Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
343.159.108.100Singapore
3104.17.6.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
267--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1933168A35565200D3A00F34CE9547078CD17450FDEABA950F9AE023DAFF2AB7849793D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:kup2EjzvCVzvTVzv4VJwM+JedK0CHJtXCZc:kuHzaVzrVzQVJwvJedKLHJFCZc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1697:BAAIFAAIBgAAAAQQAAwAAABCgBgAABAAAQIAAAAAAABQAAAAAAAAkBCgAAIAAEIEAAACEEAAEQAAECgAAAAAAAxAIAAYAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:8c7c33db33cd3230
Difference Hash:31b3b3b3b3b3b331
Wavelet Hash:3939393939393939
Color Hash:#5e3a78

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data