Security Scan Report: otymafarma.com

Redirected to:
https://otymafarma.com/login
Site favicon
Submitted: May 12, 2026, 4:16:54 PMCompleted: May 12, 2026, 4:18:27 PMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 1 country across 5 domains to perform 29 HTTP transactions. The main domain is otymafarma.com and was registered NaN years ago.

Submitted URL: https://otymafarma.com/

Effective URL: https://otymafarma.com/loginRedirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

New, unranked site impersonating Google with a credential‑stealing login form, critical IDS alerts, and obfuscated JavaScript – confirmed phishing scam.

Risk Factors
New (<7 days) unranked domain
Credential collection form
Google brand impersonation on unranked domain
Critical IDS alerts (malware C2, data exfiltration)
Highly obfuscated JavaScript
Domain age information unavailable

Details

Page Title

login | OtymaFarma

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(47%)

Domain Information

The domain name 'otymafarma.com' uses the commercial generic top-level domain (.com) without a subdomain. The core label 'otymafarma' covers 10 characters containing 4 vowels alongside 6 consonants. It segments into 5 words: o, ty, ma, farm, a. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://otymafarma.com/

Page Load Overview

8.81s
Total Load Time
27
HTTP Requests
4
Domains
645 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:196 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software47% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
47%
healthcare medical
30%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7142.251.127.84United States
AS15169Google LLC
5216.24.57.1United States
AS397273Render
552.222.236.29United States
AS16509Amazon.com, Inc.
5104.26.2.143United States
AS13335Cloudflare, Inc.
565.8.131.9United States
AS16509Amazon.com, Inc.
275--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FF43E854B814223AAC2785E0D9C8B66CF126F182EE3695FAF58D0465EFC3FF61C97604

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:DshnY3Zkg+WbQkGO0rGV4xksc64Jysq7vEDC/ZyJvlM/2:Yh4ZkkTebx/c64Jysq7vEDC/IT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:56088:gVoAaL8CC2TACiTqJZkIAKKuBGXAYEpYQAMCwVMwBBCsQXTCBYCShIiEEATMIHQUFACKhMAQVQezAtI+FRZQoGUJ0MtSFQgG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7ffffe7e7fe
Perceptual Hash:f3cc6623d9668d88
Difference Hash:102a0c08324c4d30
Wavelet Hash:fffbe0d8d8c0c0c0
Color Hash:#79d292

Other Hashes

Crop Resistant:102a0c08324c4d30

Scan History

Scan history not available

Unable to load historical scan data