Security Scan Report: githubfake-4.cmu.edu

Submitted: Oct 3, 2026, 11:45:44 PMCompleted: Oct 3, 2026, 11:46:23 PMpubliccompleted

This website contacted 21 IPs in 2 countries across 9 domains to perform 63 HTTP transactions. The main domain is githubfake-4.cmu.edu and was registered 10 years ago.

Submitted URL: https://githubfake-4.cmu.edu/

The Cisco Umbrella rank of the primary domain is #40,177 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 78%

2
Risk Score

Genuine Carnegie Mellon homepage served from the official cmu.edu domain with no forms, impersonation, or malware signals; only the odd subdomain name is mildly unusual.

Risk Factors (1)
Unusual subdomain label 'githubfake-4.cmu.edu' with no apparent relation to the CMU homepage content
Safety Factors (4)
Official university domain (cmu.edu), 41 years old, well-ranked (top 100K)
Self-branding — site name/domain own-brand match, no impersonation of another entity
No credential, password, or payment forms; the only form is a site search box
No threat-intel, YARA, IDS, or JavaScript-behavioral hits; no obfuscated or exfiltrating scripts
Domain age information unavailable

Details

Page Title

Carnegie Mellon University | CMU

Scan Type

public

Domain Name Analysis

Domain 'githubfake-4.cmu.edu' uses the sponsored educational top-level domain (.edu) with subdomain 'githubfake-4'. Count 3 characters in 'cmu' containing 1 vowel alongside two consonants. Word splitting yields 1 word: cmu. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://githubfake-4.cmu.edu/

Page Load Overview

2.15s
Total Load Time
621 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:7,915 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning67% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
67%
education
45%

Detected Features

Search
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3185.199.111.153Fastly · CDNUnited States
AS54113Fastly, Inc.
3184.24.77.151Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
3104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.14.101Google · CDNUnited States
AS15169Google LLC
318.64.211.58Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
3104.18.0.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3184.24.77.135Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
3142.251.155.119Google · CDNUnited States
AS15169Google LLC
3142.251.13.102Google · CDNUnited States
AS15169Google LLC
3104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6321--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EEB3096252E0603A010395E5AF709759AB47D4DFEA4B6680B5FD8B68DF83ED1CE1323C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:UbbTa4xx4KhAbkJ4yF9c29EVPNs9Rbk9YZlD4qblT6/fT4BI9SR0Ac5APQsu1AXR:UbbTa4xx4KJAP3s9LDU4BI9qrX3vu32

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:115167:CZrPDYaoggJG1R4EEqiSAAIQkaDFeU2ciiDREHYUAKESJgAAYlLQKICQxJjECBvNgpTZIARSCFIwXxsMERWFn4INCCRRpSEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Scan History

Scan history not available

Unable to load historical scan data