Security Scan Report: eifluis.de

Redirected to:
https://eifluis.de/login
Submitted: Nov 11, 2025, 3:56:39 AMCompleted: Nov 11, 2025, 3:57:06 AMpubliccompleted

This website contacted 4 IPs in 0 countries across 1 domain to perform 26 HTTP transactions. The main domain is eifluis.de and was registered 10 months ago.

Submitted URL: http://eifluis.de/

Effective URL:

https://eifluis.de/login
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

New, unranked domain impersonating Nextcloud with a password form – confirmed phishing scam.

Risk Factors (3)
Brand impersonation (Nextcloud) on a newly registered, unranked domain
Password collection form on a domain <7 days old
Lack of legitimate branding or official Nextcloud domain in final URL
Domain age information unavailable

Details

Page Title

Login – Nextcloud

Scan Type

public

Domain Name Analysis

The domain name 'eifluis.de' uses the German country-code top-level domain (.de) with no subdomain. The registrable portion 'eifluis' spans 7 characters containing 4 vowels alongside three consonants. Word splitting yields three words: e, if, luis. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://eifluis.de/

Page Load Overview

8.82s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:271 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software78% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
78%
documentation technical
41%
real estate property
26%
corporate
25%

Detected Features

Login Form
Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8104.21.46.36UnknownUnknown
6172.67.223.36UnknownUnknown
62606:4700:3030::6815:2e24UnknownUnknown
62606:4700:3030::ac43:df24UnknownUnknown
264--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T120F49EF25C4434357A27D31531CEAB6A331BB1035C229A8DD48E71890FFABED627257A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:T5OmCvZtB4b6chxpBOSabYKgPZtB4bSUDqNkg2EeFlqkcZhc:VgRt3ctkic

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:768319:BAxCQ5glKUHBkCCEGKOTWABUA0zAxIxBdgJYw6BA6KFAwxLQCAOaAATmEBGCugRIsgAUAQgAQIgIxbUwzQCiggVBjrFsJ/Ei

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00181818387ee100
Perceptual Hash:c99c32e31eb0c93e
Difference Hash:d0f0b2b2f1c08733
Wavelet Hash:007878f8fcfee310
Color Hash:#bf4044

Scan History

Scan history not available

Unable to load historical scan data