Security Scan Report: nfoto.no

Site favicon
Submitted: May 14, 2026, 4:53:38 PMCompleted: May 14, 2026, 4:55:48 PMpubliccompleted
Loading additional data...

Summary

This website contacted 49 IPs in 4 countries across 32 domains to perform 352 HTTP transactions. The main domain is nfoto.no and was registered NaN years ago.

Submitted URL: https://nfoto.no/fotogaver/?utm_source=nfoto.no&utm_campaign=fce6ed79c1-EMAIL_CAMPAIGN_2026_04_06_01_31_COPY_02&utm_medium=email&utm_term=0_-edac42241a-4832893&mc_cid=fce6ed79c1&mc_eid=UNIQID

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

The site hosts no phishing forms but exhibits critical IDS alerts indicating malware command‑and‑control activity; treat as high‑risk malware distribution and avoid interaction.

Risk Factors
Critical IDS alerts for malware C2 and data exfiltration
Unranked domain reputation
External analytics and CDN domains (e.g., cloudfront) used alongside malicious traffic
Domain age information unavailable

Details

Page Title

Fotogaver» Personlige gaver som kan passe alle » Nfoto

Scan Type

public

Language

🇳🇴

Norwegian

(53% confidence)

Category

blog personal website

(42%)

Domain Information

Within the Norwegian country-code top-level domain (.no), 'nfoto.no' is registered while skipping any subdomain. The registrable portion 'nfoto' spans 5 characters split between two vowels and 3 consonants. It segments into 2 words: n, foto. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nfoto.no/fotogaver/?utm_source=nfoto.no&utm_campaign=fce6ed79c1-EMAIL_CAMPAIGN_2026_04_06_01_31_COPY_02&utm_medium=email&utm_term=0_-edac42241a-4832893&mc_cid=fce6ed79c1&mc_eid=UNIQID

Page Load Overview

21.70s
Total Load Time
352
HTTP Requests
32
Domains
9.2 MB
Total Size

Language Analysis

Primary Language

🇳🇴Norwegian
Code: no
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Language Code:no
Detection Confidence:53%
Script Type:Latin
HTML Lang Attribute:nb-NO
Text Length:5,847 chars
Detector Agreement:100%
Language mismatch: Declared as nb but detected as no

Website Classification

Primary Category

blog personal website42% confidence
Type: static
Method: ml+structural

All Detected Categories

blog personal website
42%
entertainment media
35%
government public service
33%
education learning
33%
technology software
31%

Detected Features

Search
Articles
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16104.18.1.22United States
AS13335Cloudflare, Inc.
799.84.149.78United States
AS16509Amazon.com, Inc.
799.84.149.60United States
AS16509Amazon.com, Inc.
752.217.165.65Ashburn, Virginia, United States
AS16509Amazon.com, Inc.
752.72.101.220Ashburn, Virginia, United States
AS14618Amazon.com, Inc.
7185.78.209.195Norway
AS202128Iteam 10 As
765.8.102.197United States
AS16509Amazon.com, Inc.
7108.138.24.41United States
AS16509Amazon.com, Inc.
799.84.149.104United States
AS16509Amazon.com, Inc.
735.244.169.177Kansas City, Missouri, United States
AS396982Google LLC
35249--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F344A7B2AC643C37216B48C87065275EF5E3C61BCB8344907BB993C757E2E907A67A1C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:HcASPiEDxSe7twXp4ScGaEkXpyScnXzg1XpYScj8i+MAgwaVXp/ScqqlABXpsSc1:Hc/xSeZyJQr0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:253469:AiCAGUOZhaQx2BAJpBBaeAOM4IMSZwYgAkIeDZoKIbAC6IHGarzRJItwuUMAUQicIJwAFyUrRAFABAGBIpNLIrAhBkghtKBQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Scan History

Scan history not available

Unable to load historical scan data