Security Scan Report: ww5.llinoislottery.com

Submitted: Nov 16, 2025, 3:24:02 PMCompleted: Nov 16, 2025, 3:24:33 PMpubliccompleted
Loading additional data...

Summary

This website contacted 34 IPs in 4 countries across 10 domains to perform 26 HTTP transactions. The main domain is ww5.llinoislottery.com and was registered NaN years ago.

Submitted URL: https://ww5.llinoislottery.com/

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High risk site impersonating Illinois Lottery; do not trust or provide any credentials

Risk Factors
Malicious Indicators of Compromise (suspicious IP address)
Typo‑squatting brand impersonation of Illinois Lottery
Domain not in Cisco Umbrella top 1M (low reputation)
Domain age information unavailable

Details

Page Title

llinoislottery.com

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

gambling betting

(54%)

Domain Information

The domain name 'ww5.llinoislottery.com' uses the commercial generic top-level domain (.com) and includes subdomain 'ww5'. The second-level label 'llinoislottery' is 14 characters long containing five vowels alongside nine consonants. Segmentation suggests 4 words: lli, no, is, lottery. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ww5.llinoislottery.com/

Page Load Overview

6.61s
Total Load Time
26
HTTP Requests
10
Domains
92 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:101 chars
Detector Agreement:50%

Website Classification

Primary Category

gambling betting54% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

gambling betting
54%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
03.248.162.96Dublin, Leinster, Ireland
AS16509AMAZON-02
076.223.26.96United States
AS16509AMAZON-02
0208.91.196.46British Virgin Islands
AS40034CONFLUENCE-NETWORK-INC
034.251.101.162Dublin, Leinster, Ireland
AS16509AMAZON-02
013.35.58.44United States
AS16509AMAZON-02
087.248.119.251United Kingdom
AS203220Yahoo-UK Limited
0188.114.96.3United States
AS13335CLOUDFLARENET
013.107.246.44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
013.248.148.254United States
AS16509AMAZON-02
0199.191.50.135British Virgin Islands
AS40034CONFLUENCE-NETWORK-INC
2634--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12DA2FA27BA931504F51B806ADBAA7359331C5087F90BCC68BA9C1354DF4E7D63293BAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:UexcYoHSiFsNusOlJUDhFVZc6i81H5/noTA+BHeYoHsfO5/G:UexCSiFsDOSFV1i81HZoTAwksfCO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22689:QBQQAgUQxs0RE4XACIIaCAABCjVkdMoRJwkRHmYaBATgSEgAkIeAJBygAAPKUtAyBWqWQSHaMAA4IAwK4KgbIMZMI0MSNwCA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3cc3ffdb52181800
Perceptual Hash:c4e44b1a1b9b9b93
Difference Hash:7196969696b2b282
Wavelet Hash:3ce7ffdf52181800
Color Hash:#d27992

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data