Security Scan Report: sp887622.sitebeat.crazydomains.com

Site favicon
Submitted: Oct 29, 2025, 5:51:59 PMCompleted: Oct 29, 2025, 5:52:41 PMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 2 countries across 5 domains to perform 31 HTTP transactions. The main domain is sp887622.sitebeat.crazydomains.com.

Submitted URL: https://sp887622.sitebeat.crazydomains.com/

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing site harvesting credentials; avoid and report.

Risk Factors
Disguised password field (type='text' with password placeholder)
Hidden password field not visible in screenshot
Password field without username/email field
Unicode evasion in form inputs
Newly registered, unranked domain mimicking a legitimate service
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(50%)

Domain Information

The domain 'sp887622.sitebeat.crazydomains.com' uses the commercial generic top-level domain (.com), featuring subdomain 'sp887622.sitebeat'. Count 12 characters in 'crazydomains' with 4 vowels and 8 consonants. Splitting it apart reveals two words: crazy, domains. Median word length comes out to 6 characters. 'crazy' most strongly signals English. You will also see it in Chinese (Pinyin) and French contexts. Net impression: English phrase.

Screenshot

Security scan screenshot of https://sp887622.sitebeat.crazydomains.com/

Page Load Overview

18.05s
Total Load Time
31
HTTP Requests
5
Domains
1.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:997 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9172.67.70.60United States
AS13335CLOUDFLARENET
234.117.140.48Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
2103.67.235.120Perth, Western Australia, Australia
AS38719Dreamscape Networks Limited
2104.26.7.16United States
AS13335CLOUDFLARENET
2172.66.160.115United States
AS13335CLOUDFLARENET
22606:4700:10::6814:255bUnited States
AS13335CLOUDFLARENET
22606:4700:20::681a:710United States
AS13335CLOUDFLARENET
22606:4700:10::ac42:a073United States
AS13335CLOUDFLARENET
22606:4700:20::ac43:463cUnited States
AS13335CLOUDFLARENET
22606:4700:20::681a:610United States
AS13335CLOUDFLARENET
3112--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DD8364A1981B1012B28B5CDA33CFBB19A10D634BA840DA257BFC279C6FDDD7A127171D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:VSP7g7KsWYqEuUrDR4Nw75777u7L7ptfC/FFHKX9N/ifldvSPVN/iflFHKX9dvS6:5+zmuvz42q6dNsNhRqUC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:84828:EDEIAyDCFQeWN4EIIEACBRpMSBAsGswiCFScALQWBg6YAmoCAhCwARWgGRSaZs9HVArEexIBRUDiESJEgCkMrFcCBRYhAAoU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data