Security Scan Report: qr-codes.io

Redirected to: https://www.amazon.com/ap/signin?yyy

Site favicon
Submitted: Dec 9, 2025, 10:20:33 PMCompleted: Dec 9, 2025, 10:21:37 PMpubliccompleted
Loading additional data...

Summary

This website contacted 62 IPs in 3 countries across 12 domains to perform 36 HTTP transactions. The main domain is amazon.com.

Submitted URL: https://qr-codes.io/dscuyM

Effective URL: https://www.amazon.com/ap/signin?yyyRedirected

The Cisco Umbrella rank of the primary domain is #840,595 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Site impersonates Amazon using a fresh, low‑rank domain and redirects to Amazon login – high‑risk phishing.

Risk Factors
Brand impersonation on an unusual, low‑reputation domain
Newly registered domain with no established reputation
Suspicious redirect chain (qr-codes.io → amazon.com login)
Low ranking in Cisco Umbrella for a site claiming Amazon
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇺🇸

English

(65% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'qr-codes.io' uses the British Indian Ocean Territory country-code top-level domain (.io) while skipping any subdomain. The registrable portion 'qr-codes' spans 8 characters holding two vowels versus five consonants, plus one hyphen. It segments into 2 words: qr, codes. Median word length is 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://qr-codes.io/dscuyM

Page Load Overview

26.74s
Total Load Time
36
HTTP Requests
12
Domains
443 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:65%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:65%
Script Type:Latin
Text Length:130 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
36157.240.253.1Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
034.231.148.183Ashburn, Virginia, United States
AS14618AMAZON-AES
0142.250.185.68United States
AS15169GOOGLE
044.209.46.160Ashburn, Virginia, United States
AS14618AMAZON-AES
0142.251.140.168United States
AS15169GOOGLE
020.57.3.79Boydton, Virginia, United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
018.245.46.109United States
AS16509AMAZON-02
03.209.224.160Ashburn, Virginia, United States
AS14618AMAZON-AES
0108.138.26.92United States
AS16509AMAZON-02
03.231.140.64Ashburn, Virginia, United States
AS14618AMAZON-AES
3662--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117833AD9F650703365B321B9A0AF550B223B136379888891B81CE4E43F79ADE4367F6D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:dfFIiqYxoHjekhGTLveBsAADtQVWcSA4uT9:dfFHxoDek0/v8sAAUXwup

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:83843:axAAUiEguA7xC4GAhZAIYh8BtAchC4CBlCCJkGRgejhgQKwxAa1AAZSYRCuoELCixRYZG8pGBE8AEKRCAFB14hYwARohEoQq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3ffffffffffff
Perceptual Hash:b33333332286cece
Difference Hash:0e0c000000000000
Wavelet Hash:c3c3ffff00000000
Color Hash:#ac5397

Other Hashes

Crop Resistant:0e0c000000000000

Scan History

Scan history not available

Unable to load historical scan data