Security Scan Report: zandrix.mypi.co

Submitted: Oct 31, 2025, 5:51:58 AMCompleted: Oct 31, 2025, 5:55:21 AMpubliccompleted
Loading additional data...

Summary

This website contacted 20 IPs in 2 countries across 6 domains to perform 292 HTTP transactions. The main domain is zandrix.mypi.co.

Submitted URL: https://zandrix.mypi.co/mail/new/[email protected]

AI Security Verdict

High Risk

Confidence: 95%

7
Risk Score

High‑risk phishing page using a malicious dynamic domain to lure credentials.

Risk Factors
Malicious Indicators of Compromise match on primary domain
Dynamic suspicious domain (mypi.co) used in subdomain
Credential‑harvesting prompt without a real authentication service
Domain age information unavailable

Details

Page Title

Yao Session Expired

Scan Type

public

Language

🇺🇸

English

(67% confidence)

Category

unknown

(0%)

Domain Information

Domain 'zandrix.mypi.co' uses the Colombian country-code top-level domain (.co) with subdomain 'zandrix'. The second-level label 'mypi' is 4 characters long with one vowel and 3 consonants. It segments into two words: my, pi. Expect 2 characters per word on average. 'my' most strongly signals Afrikaans. Usage also turns up in Chinese (Pinyin) and English contexts.

Screenshot

Security scan screenshot of https://zandrix.mypi.co/mail/new/?jivsbsdnoo=ni5@yao.se

Page Load Overview

6.46s
Total Load Time
292
HTTP Requests
6
Domains
379 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:67%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:67%
Script Type:Latin
HTML Lang Attribute:en
Text Length:112 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
286162.241.114.170United States
AS19871NETWORK-SOLUTIONS-HOSTING
26142.250.185.196United States
AS15169GOOGLE
14142.250.184.228United States
AS15169GOOGLE
142606:4700:3108::ac42:2918United States
AS13335CLOUDFLARENET
1465.9.175.79United States
AS16509AMAZON-02
142606:4700:20::681a:82cUnited States
AS13335CLOUDFLARENET
142606:4700:20::ac43:45e2United States
AS13335CLOUDFLARENET
14172.67.69.226United States
AS13335CLOUDFLARENET
1465.9.175.126United States
AS16509AMAZON-02
142a00:1450:4001:827::2004Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
29220--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E1513F6411F548AF108791E1B9E1BE89A994C307CB6B8E5CF0FD09A23FC6D524C13678

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:n9mdhw5bUIBaDpoMeONtgv/UXiBvT0lgbCn+k2jHqr6QNh2OSi:n9swbUIYteOQvsSBvU1cqvbSi

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2915:AJABEMAAiAAAgAAAEAAACAAEAAABwhQAQQCjAABEQASgMAAACABEAAKYICiYAgAlBgQBhALAAkAAA2CAAQgAAAABAAAAABAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:99cc663399cccc99
Difference Hash:300cb2b2b2321000
Wavelet Hash:00001818fbfbdfcf
Color Hash:#40bfae

Other Hashes

Crop Resistant:300cb2b2b2321000

Scan History

Scan history not available

Unable to load historical scan data