Security Scan Report: lop98z.icu

Redirected to: https://lop98z.icu/o/qpp4h/1765272322020#selectedbank9&BLNC_VB

Submitted: Dec 9, 2025, 5:38:28 PMCompleted: Dec 9, 2025, 5:39:11 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 2 countries across 2 domains to perform 54 HTTP transactions. The main domain is lop98z.icu and was registered NaN years ago.

Submitted URL: https://lop98z.icu/o/qpp4h/1765272322020#selectedbank9

Effective URL: https://lop98z.icu/o/qpp4h/1765272322020#selectedbank9&BLNC_VBRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

New, unranked domain impersonating Bank Millennium with suspicious redirects and credential‑harvesting form – confirmed phishing scam.

Risk Factors
Brand impersonation on a newly registered domain
Critical domain age (<7 days)
Circular redirect indicating URL manipulation
Credential‑harvesting form (account balance field) on suspicious site
Unranked domain with low reputation
Domain age information unavailable

Details

Page Title

Bank Millennium 1765272322020

Scan Type

public

Language

🇵🇱

Polish

(41% confidence)

Category

blog personal website

(100%)

Domain Information

You're looking at domain 'lop98z.icu' on the .icu top-level domain and has no subdomain. Its registrable label 'lop98z' stretches across 6 characters holding one vowel versus three consonants, notching two digits. Segmentation suggests 3 words: lop, 98, z. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lop98z.icu/o/qpp4h/1765272322020#selectedbank9

Page Load Overview

8.13s
Total Load Time
54
HTTP Requests
2
Domains
1.5 MB
Total Size

Language Analysis

Primary Language

🇵🇱Polish
Code: pl
Confidence:41%
Script:Latin
Direction:ltr

Detection Details

Language Code:pl
Detection Confidence:41%
Script Type:Latin
HTML Lang Attribute:ru
Text Length:4,943 chars
Detector Agreement:50%
Language mismatch: Declared as ru but detected as pl

Website Classification

Primary Category

blog personal website100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

blog personal website
100%
finance banking
100%
education learning
100%
cryptocurrency blockchain
100%
government public service
100%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1586.54.24.12Latvia
AS208885Noyobzoda Faridduni Saidilhom
1352.48.38.99Dublin, Leinster, Ireland
AS16509AMAZON-02
1354.216.83.132Dublin, Leinster, Ireland
AS16509AMAZON-02
1399.81.234.0Dublin, Leinster, Ireland
AS16509AMAZON-02
544--

Detected Technologies2

JQueryv3.6.0
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11CC318B880F10537540786AAAFF6675A2EA9D00BCA46D94477EC82E2DFC7EC1D90731D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:pEjliWb0OtxlyJEjlit0YstawlyqEjlia0YstawlysnfLre2:pEjAA8JEjAY0xqEjAb0x6re2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:125360:ECBMMKDIApIYJogPhts4RBiEFEQh8kKCgG8pAIkQAQCAiGCPidItRDKASBo0UEFwRPAyWlBqGyVIiHFAEEUwMgQQGRCWQIgx

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:b8b8f8b8b8f8e0e0
Perceptual Hash:cdcd36498862b277
Difference Hash:7232223232a24240
Wavelet Hash:b8f8b8b8b8f8e0e0
Color Hash:#2dd253

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data