Security Scan Report: openai-bonus.com

Site favicon
Submitted: Oct 2, 2026, 12:00:52 PMCompleted: Oct 2, 2026, 12:01:28 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Day-old openai-bonus.com impersonates openai.com with a fake Cloudflare check that tells users to paste clipboard commands into Terminal — a ClickFix malware-delivery page, and its URL is flagged as malware by 2 independent threat feeds.

Risk Factors (5)
Impersonation of OpenAI's brand (openai.com shown as header) on an unrelated, day-old domain openai-bonus.com
Multi-feed content-malware threat-intelligence hit against the URL (2 independent sources)
ClickFix-style fake CAPTCHA instructing victims to paste clipboard commands into Terminal/Windows Run — OS-level malware execution lure
Suspicious clipboard activity (4 events) indicating automatic clipboard manipulation
Domain ≤1 day old and absent from Cisco Umbrella top 1M rankings
Domain age information unavailable

Details

Page Title

Just a moment...

Scan Type

public

Domain Name Analysis

You're looking at domain 'openai-bonus.com' on the commercial generic top-level domain (.com). The core label 'openai-bonus' covers 12 characters holding six vowels versus five consonants; bonus characters include 1 hyphen. It segments into four words: open, a, i, bonus. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://openai-bonus.com/

Page Load Overview

0.44s
Total Load Time
118 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-us
Text Length:1,974 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software69% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
69%
documentation technical
69%
adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
340.114.178.124Azure · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
72--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B714A310A680E31A53073B7B261DB6A4E43509AEBD607587D6CFFD14E29512FFB63A30

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:ASNP5X3DJT2PmT6PCe/T0ZERK1HqP3WQI/h+bqSC7yMJ/skdW6XzDqTxPpCBbgqe:A2eambMC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:199085:wWRMBcBQEA4RiioDBESATJCoVigNAbTVlNpQC/OgBIwlBFeQEQlAYQOiVIDqIEhCgAQ4EARMRBrJiAJAoSAJIpQEgorCAsEi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cfcfcfffffffffe7
Perceptual Hash:b83830ccc7c7c7c6
Difference Hash:109828000000000c
Wavelet Hash:fcc4d0f0f0f0f0c0
Color Hash:#ac539c

Other Hashes

Crop Resistant:109828000000000c

Scan History

Scan history not available

Unable to load historical scan data