Security Scan Report: t.co

Redirected to: blob:https://splay.vip/6c3d2880-8612-464c-96a9-d0231d53b345

Site favicon
Submitted: Dec 4, 2025, 9:58:47 AMCompleted: Dec 4, 2025, 9:59:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 37 IPs in 3 countries across 7 domains to perform 11 HTTP transactions. The main domain is .

Submitted URL: https://t.co/hM2ckSNNqH

Effective URL: blob:https://splay.vip/6c3d2880-8612-464c-96a9-d0231d53b345Redirected

The Cisco Umbrella rank of the primary domain is #1,176 of the top 1 million websitesTop 10K Site

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Phishing page impersonating Capital One; confirmed scam.

Risk Factors
Disguised password fields
Hidden password fields
Unicode evasion in form fields
Brand impersonation on untrusted domain
Credential harvesting forms on a newly registered domain
URL manipulation (blob: URL) after redirects
Domain age information unavailable

Details

Page Title

Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(27%)

Domain Information

You're looking at domain 't.co' on the Colombian country-code top-level domain (.co). The second-level label 't' is 1 characters long containing 0 vowels alongside 1 consonant. Segmentation suggests 1 word: t. Median word length is 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://t.co/hM2ckSNNqH

Page Load Overview

11.47s
Total Load Time
11
HTTP Requests
7
Domains
71 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,565 chars
Detector Agreement:67%

Website Classification

Primary Category

finance banking27% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
245.79.134.169Cedar Knolls, New Jersey, United States
AS63949Akamai Connected Cloud
235.157.26.135Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
1172.66.0.227United States
AS13335CLOUDFLARENET
1151.101.2.137San Francisco, California, United States
AS54113FASTLY
192.123.104.40Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
1154.37.221.112Hong Kong, Hong Kong
AS979NETLAB-SDN
1142.250.185.138United States
AS15169GOOGLE
0151.101.130.137San Francisco, California, United States
AS54113FASTLY
0142.250.185.170United States
AS15169GOOGLE
063.176.8.218Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
1137--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12F436636619341BA9CB3CAC857EB2B463E849887E0C9D12477AC9AD84F838D5D47D3DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:Q7FSF3FuWFzF+fs8utovnh8utovWX93mXTHarCt1WtXL/plyA7qvE6mw:yQl0WxMTvCvQ+KCt1WtXLRlyA7q86mw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:59363:gyRnLEkqJ4EiMAWA0W06EclZiAwDaQbJAZSipgUCBCaJBCACIFFmwJETIMTzAmwpIkxGiFlCso5p3lDRQQoBEWAIACHadAIF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9bbe46a6bebdbdad
Perceptual Hash:f7748c8c9d362626
Difference Hash:36644c4a68696969
Wavelet Hash:93be043c2c3d3d2d
Color Hash:#3a7778

Other Hashes

Crop Resistant:36644c4a68696969

Scan History

Scan history not available

Unable to load historical scan data