Security Scan Report: metro.at

Redirected to: https://www.metro.at/

Submitted: Dec 24, 2025, 8:06:18 PMCompleted: Dec 24, 2025, 8:08:56 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 2 domains to perform 19 HTTP transactions. The main domain is metro.at and was registered NaN years ago.

Submitted URL: https://metro.at

Effective URL: https://www.metro.at/Redirected

The Cisco Umbrella rank of the primary domain is #844,695 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Phishing site mimicking Metro Austria; likely malicious.

Risk Factors
Brand impersonation on a recently registered, low‑ranked domain
Recent domain registration (<180 days) increases suspicion
Low Cisco Umbrella ranking for a brand claim
Domain age information unavailable

Details

Page Title

403

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

government public service

(50%)

Domain Information

The domain 'metro.at' uses the Austrian country-code top-level domain (.at) with no subdomain. The second-level label 'metro' is 5 characters long holding two vowels versus 3 consonants. Word splitting yields 1 word: metro. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://metro.at

Page Load Overview

76.48s
Total Load Time
82
HTTP Requests
4
Domains
618 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de-AT
Text Length:7,385 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service50% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
50%
technology software
39%
e-commerce shopping
33%
finance banking
31%
corporate business
28%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8223.50.131.149Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
821--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1748164A7C34CC2EABC4793C49DC50018747AE8DFB2F095989E681712DC8E9FB981C4D9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:AIComhfLaj0sEsW7wF73bJKxgm6XgWx5sRQrqBn:Alo6OjhWqzbJgcN5MI8n

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3827:ICAQAEAAgAhAAAAAEBABDFAIAQCAyBDgQIAAIgBEEQIDYBWAgACCGIFpAUIEBBAUAQiEAAAAQEHAAAgAAIiRgAAAACACABiA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffe7ffffffffff
Perceptual Hash:f2725c5c58727272
Difference Hash:54884d0c10000000
Wavelet Hash:002000000f0f0f0f
Color Hash:#93bf40

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data