Security Scan Report: billsnotes.com

Redirected to: https://billsnotes.com/lock.php?redirect=%2F

Submitted: Mar 17, 2026, 10:46:06 PMCompleted: Mar 17, 2026, 10:47:26 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 6 HTTP transactions. The main domain is billsnotes.com and was registered NaN years ago.

Submitted URL: https://billsnotes.com/

Effective URL: https://billsnotes.com/lock.php?redirect=%2FRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

New unranked site with only a PIN field; likely credential phishing – classified as confirmed scam.

Risk Factors
New domain (<7 days) with login form
Password field without accompanying username field
Single credential‑harvesting form only
Unranked domain (not in top 1 M sites)
Domain age information unavailable

Details

Page Title

BillsNotes — Unlock

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(57%)

Domain Information

Domain 'billsnotes.com' uses the commercial generic top-level domain (.com) with no subdomain. The registrable portion 'billsnotes' spans 10 characters containing 3 vowels alongside 7 consonants. It segments into 2 words: bills, notes. Expect 5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://billsnotes.com/

Page Load Overview

1.34s
Total Load Time
6
HTTP Requests
3
Domains
63 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:81 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking57% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
57%
news media journalism
40%
government public service
39%
cryptocurrency blockchain
33%
healthcare medical
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
292.113.16.85Frankfurt am Main, Hesse, Germany
AS47583Hostinger International Limited
2142.251.127.94United States
AS15169Google LLC
2142.250.187.234United States
AS15169Google LLC
63--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13FE184A725F326752A2362A927EB530A3174D003D508ED287FDD61D4CFC75F999A270C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:HhcVSomO6RGHUaS9mie9mBWacs4mreoJ3GxSuvqSIdj:H+0dberxS8i

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7158:pWEyAEAIIALQBQhBE9Ec1CU0AAgMCImoVAcgWhiHYcEUCYBADBAZwRQwrE8VRE6KQAQRBDDyk1sDfAiMECAEoQkBgASgOSgN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818180000
Perceptual Hash:99666699cc339966
Difference Hash:0830323232320008
Wavelet Hash:f0f8d8d8dcdcc0c0
Color Hash:#b7e06c

Other Hashes

Crop Resistant:0830323232320008

Scan History

Scan history not available

Unable to load historical scan data