Security Scan Report: evilginx.com

Site favicon
Submitted: Nov 24, 2025, 8:06:02 AMCompleted: Nov 24, 2025, 8:07:08 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 3 domains to perform 19 HTTP transactions. The main domain is evilginx.com and was registered NaN years ago.

Submitted URL: https://evilginx.com/

AI Security Verdict

Safe Website

Confidence: 95%

0
Risk Score

No security concerns identified; site appears legitimate.

Safety Factors
Well‑established domain with minimal risk level
No phishing or malware indicators detected
Domain age information unavailable

Details

Page Title

Evilginx Pro

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(50%)

Domain Information

The domain name 'evilginx.com' uses the commercial generic top-level domain (.com) with no subdomain. Its registrable label 'evilginx' stretches across 8 characters with 3 vowels and five consonants. It segments into 4 words: evil, g, in, x. Expect 1.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://evilginx.com/

Page Load Overview

1.21s
Total Load Time
19
HTTP Requests
3
Domains
8.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,405 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1546.101.195.123Frankfurt am Main, Hesse, Germany
AS14061DIGITALOCEAN-ASN
7142.250.181.234United States
AS15169GOOGLE
3216.58.212.131United States
AS15169GOOGLE
2142.250.186.99United States
AS15169GOOGLE
22a00:1450:4001:81c::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:82a::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
1216.58.206.74United States
AS15169GOOGLE
197--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A9E2F835B244067B678785DBE4A7F35DE0FAC28FC7278884E3FC91A217C2C94E922165

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:+fdfe/tELEExQNqTUP3VxFGUQ8saL8p8z8ru8yjWDJnsEQbNF+JX8v5NfBVDeLbg:+f8BNnFxFGUQ1AqEl6De9bL+hzY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:32600:Y4EBhkRKsAGEcukBKnQgAChoBEAGZEAKJzE18bAVJG0JVcAHIJVECyYCkWhMBCtUIwHAUkgBQEAEAwyDFGgJAOfSA0CoQABZ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:07393b1b18003018
Perceptual Hash:8ca4b67231b3b9a6
Difference Hash:8d75723331216971
Wavelet Hash:073d3f1b19013d3d
Color Hash:#8b79d2

Scan History

Scan history not available

Unable to load historical scan data