Security Scan Report: spr.2tb.fit

Redirected to: https://spr.2tb.fit/?YurmHxeMxXNan9ZB8MXLBzeKjSyBEqlPCtRbJbbua96dA5iR9DRCrdX80CmPSoAy0VVphBSoDlC75Dj2hdckIIclzta4oLF60gg1&s1

Submitted: Oct 16, 2025, 6:47:36 AMCompleted: Oct 16, 2025, 6:48:13 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 1 country across 4 domains to perform 24 HTTP transactions. The main domain is spr.2tb.fit and was registered NaN years ago.

Submitted URL: https://spr.2tb.fit/?is

Effective URL: https://spr.2tb.fit/?YurmHxeMxXNan9ZB8MXLBzeKjSyBEqlPCtRbJbbua96dA5iR9DRCrdX80CmPSoAy0VVphBSoDlC75Dj2hdckIIclzta4oLF60gg1&s1Redirected

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

Site uses URL manipulation and brand impersonation to harvest personal data – high‑risk phishing.

Risk Factors
URL manipulation (browser location bar differs from actual content source)
Brand impersonation of Sparkasse on an unranked, recently registered domain
Collection of personal data via hidden form fields
Unranked low‑reputation domain (not in Cisco Umbrella top 1M)
Recent domain registration (< 1 year) increasing suspicion
Domain age information unavailable

Details

Page Title

️️

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

entertainment media

(53%)

Domain Information

Domain 'spr.2tb.fit' uses the .fit top-level domain and includes subdomain 'spr'. The second-level label '2tb' is 3 characters long containing zero vowels alongside 2 consonants, plus 1 digit. Splitting it apart reveals 2 words: 2, tb. Median word length comes out to 1.5 characters. 'tb' is most common in Danish usage. You may catch it in German and English as well.

Screenshot

Security scan screenshot of https://spr.2tb.fit/?is

Page Load Overview

14.62s
Total Load Time
24
HTTP Requests
4
Domains
35 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
Text Length:19,605 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media53% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

entertainment media
53%
adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8188.114.96.3United States
AS13335CLOUDFLARENET
2172.67.170.16United States
AS13335CLOUDFLARENET
2104.21.47.24United States
AS13335CLOUDFLARENET
2188.114.97.3United States
AS13335CLOUDFLARENET
2203.161.63.11United States
AS22612NAMECHEAP-NET
22a06:98c1:3120::3United States
AS13335CLOUDFLARENET
22606:4700:3031::6815:2f18United States
AS13335CLOUDFLARENET
22a06:98c1:3121::3United States
AS13335CLOUDFLARENET
22606:4700:3035::ac43:aa10United States
AS13335CLOUDFLARENET
249--

Detected Technologies1

JQueryv3.7.1
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CA93896FA1E30A3B81C689D36E3253367B78C45ACB9118717E9E97990BC7CC5D28718C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:CLb1CuYPb1CuYYJURR93Hj5VIg42lGlxW3oNbYq3U5UDY45:CLkuikulT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:97285:hAZqMCGACgBFQUAkIYtEDGKCPIKASgAU2JYgAAo4qAA57QDAEEDUTClKDggQgqpyYmuHqGSQENzMxiFSAJUACgqoSUIVSVjk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00f3f2fee0000000
Perceptual Hash:e4e41a19d9f046e7
Difference Hash:9b66c682029b8111
Wavelet Hash:c3fff3fffa000000
Color Hash:#87abc5

Scan History

Scan history not available

Unable to load historical scan data