Security Scan Report: palmsafe.live

Redirected to: https://palmsafe.live/signup/verify-registration.php

Site favicon
Submitted: Mar 5, 2026, 3:56:29 AMCompleted: Mar 5, 2026, 3:57:46 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 1 HTTP transaction. The main domain is palmsafe.live and was registered NaN years ago.

Submitted URL: http://palmsafe.live/signup/verify-registration.php

Effective URL: https://palmsafe.live/signup/verify-registration.phpRedirected

AI Security Verdict

Confirmed Scam

Confidence: 94%

10
Risk Score

New, unranked site impersonating a bank and collecting credentials – confirmed phishing scam.

Risk Factors
Brand impersonation of a financial institution on a brand‑new domain
Credential harvesting form with multiple password fields
Domain age < 7 days with login/registration form
Unranked domain (not in Cisco Umbrella top 1M)
Lack of any legitimate site content or additional functional forms
Domain age information unavailable

Details

Page Title

Registration - International Reserved Bank

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(58%)

Domain Information

Domain 'palmsafe.live' uses the .live top-level domain. The second-level label 'palmsafe' is 8 characters long split between 3 vowels and 5 consonants. Tokenizing the label suggests 2 words: palm, safe. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://palmsafe.live/signup/verify-registration.php

Page Load Overview

1.70s
Total Load Time
37
HTTP Requests
3
Domains
213 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:3,613 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking58% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
58%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1392.204.41.13Strasbourg, Grand Est, France
AS29066velia.net Internetdienste GmbH
12142.251.208.170United States
AS15169Google LLC
12152.3.138.25Durham, North Carolina, United States
AS13371Duke University
373--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AE7350125CE0586BA0AB4DDD49E4EA1C69F88303ED36058DF65CC7E18FA3E5ECA73215

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:aCs7PUPlZv8KZe2Tcc2GVJM8/zwYeIgQmG4iwA1wkerUPpUj1yEt:aCn8tyP0lA1wkerKA1yEt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:74064:FAAGeIiCSELSQ0qGipxWgTDgCEgkMAD1YAghgCAKWCeIQYkKnzsqeCz/aYABSozIAAlBAOahhC1ABHAyBJGEJZYkDBUhpQJh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f0f0f0f0f0f0f0f
Perceptual Hash:b1e3dc07817daa15
Difference Hash:5a1a1adada1b1a1a
Wavelet Hash:0f0f0f0f0f0f0f0f
Color Hash:#ac8e53

Scan History

Scan history not available

Unable to load historical scan data