Security Scan Report: rmuwslkop.gzb88.com

Site favicon
Submitted: Sep 13, 2026, 3:54:27 PMCompleted: Sep 13, 2026, 3:54:47 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 78%

9
Risk Score

Unbranded 'enterprise mail' login page on a random subdomain with a victim email in the URL — a credential-phishing surface. Do not enter credentials.

Risk Factors (5)
Login form capturing email and password on a suspicious, unranked random subdomain
Victim email address embedded in URL on a different domain than the email provider
No brand identity, ownership information, or legitimate mail-service backing
High-entropy subdomain label consistent with disposable phishing infrastructure
No threat-intel or IDS corroboration, but page content itself is a credential-capture surface
Domain age information unavailable

Details

Page Title

企业邮箱登录

Scan Type

public

Domain Name Analysis

The domain 'rmuwslkop.gzb88.com' uses the commercial generic top-level domain (.com) with subdomain 'rmuwslkop'. The registrable portion 'gzb88' spans 5 characters split between 0 vowels and 3 consonants, plus two digits. Tokenizing the label suggests three words: gz, b, 88. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://rmuwslkop.gzb88.com/?m=hr@download11.com

Page Load Overview

3.70s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-CN
Text Length:189 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical68% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
68%
corporate business
68%
technology software
36%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4192.252.179.184United States
AS152194CTG Server Limited
41--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E81209231271363DA497C559B7D2934E3134E003E5064A68BE5C6E5CCFCEEE265B3798

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:MCK4sOahiAZ16/05hApTieqBifisf+iGWD4NWwQMfTA9zz7YfrY7XF9oT+ViOcK8:KqI8qRrWZXPGX1XsXxVzsP

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:9694:FBBkCAkCwKWAwC0ChXwZ4mIIxEgQTYlABCIBmEgATDBlDFmGgLiR9QlsEQLGQibCJH3UEEhBECggWBAWJIBLAYFZBgqhM8QH

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00fffffffbfbffff
Perceptual Hash:ed12136d1e126d6d
Difference Hash:00082c2c32720c22
Wavelet Hash:00c10f0fb3b1c0ff
Color Hash:#6ce0bf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data