Security Scan Report: fotmob.en.download.it

Site favicon
Submitted: Dec 9, 2025, 10:35:06 PMCompleted: Dec 9, 2025, 10:36:42 PMpubliccompleted
Loading additional data...

Summary

This website contacted 37 IPs in 4 countries across 14 domains to perform 83 HTTP transactions. The main domain is fotmob.en.download.it and was registered NaN years ago.

Submitted URL: https://fotmob.en.download.it/android

The Cisco Umbrella rank of the primary domain is #230,054 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 88%

7
Risk Score

High risk due to brand impersonation on a non‑official domain.

Risk Factors
Brand impersonation on an unusual domain
Low ranking for brand claim (Cisco Umbrella rank > 100k)
Domain does not match official FotMob domain (fotmob.com)
Domain age information unavailable

Details

Page Title

FotMob APK for Android - Free download

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(73%)

Domain Information

You're looking at domain 'fotmob.en.download.it' on the Italian country-code top-level domain (.it), featuring subdomain 'fotmob.en'. Count 8 characters in 'download' with three vowels and 5 consonants. Word splitting yields one word: download. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://fotmob.en.download.it/android

Page Load Overview

31.50s
Total Load Time
83
HTTP Requests
14
Domains
299 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:9,469 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software73% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
73%
phishing/scam
20%

Detected Features

Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11165.232.93.253Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
2142.250.186.170United States
AS15169GOOGLE
2172.67.141.193United States
AS13335CLOUDFLARENET
2216.239.32.36United States
AS15169GOOGLE
266.102.1.155United States
AS15169GOOGLE
2104.20.23.96United States
AS13335CLOUDFLARENET
2206.189.8.180Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
2188.166.57.74Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
2104.248.196.220Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
2142.250.184.232United States
AS15169GOOGLE
8337--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16554D832AEB8C06DA40B82A4DD70970E91A6C283D195DAEC76ED393CCF856D75D1324F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:/tMjGVtMjGeIC/sH7MLX5ROoWf1HYqK3RSUsh0:tC/sH7MLHwKX2K

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:286127:FE1rQAQQFgzgUAmlriiF0MARyIoyTCI2TuGgiBmBysAGIILIRNQAtAVpQAIVEBAAKg4M4ERAhRiaxpMqJCQLQKgWWlVRCqGB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00fbffdfdfcfdfcf
Perceptual Hash:b95b5b1b1b131313
Difference Hash:d9223c363e1e381e
Wavelet Hash:0098ffc38f83cf83
Color Hash:#2d8684

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data