Security Scan Report: weitransfer.cfd

Submitted: Sep 19, 2026, 9:47:28 AMCompleted: Sep 19, 2026, 9:47:50 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Highest-weight signal is a multi-source malware (RAT) report on the primary domain, reinforced by a Turnstile-gated landing page and 4 cross-domain redirects; no credential form was present. Treat as malicious and avoid.

Risk Factors
Multi-source threat-intelligence match reporting a RAT (malware) on the primary domain
Turnstile-gated landing page with hidden routing field (originalPath)
Excessive cross-domain redirect chain (4 redirects)
Machine-learning classifier flags phishing/scam content
No reputation/ranking for the domain
Domain age information unavailable

Details

Page Title

Verification Required

Scan Type

public

Domain Name Analysis

Domain 'weitransfer.cfd' uses the .cfd top-level domain without a subdomain. The registrable portion 'weitransfer' spans 11 characters containing four vowels alongside seven consonants. It segments into two words: wei, transfer. Median word length comes out to 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://weitransfer.cfd

Page Load Overview

4.65s
Total Load Time
443 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:34 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing/scam40% confidence
Type: static
Method: structural

All Detected Categories

phishing/scam
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
204--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T172D1C9563AA71011E453A1A53BBAC7493A64E213C64FC8A87FDC7118CF89ED5DCA3B1C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:tIGk/xg86UwemeWYC0nrdy/cUyJkHNLtTSnx/9g:tIYtLdSnx/C

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6218:cEJByAAPwAAGEzHEAAhTIIRgIBBBaIAgkAXAAlBAnygQOEASkADTAoAUkAAItTAT4AqhCAhWgPiDg5AAHoABJHZQiAEQosgI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffe7e7ffff
Perceptual Hash:b3cccc3399cc2633
Difference Hash:0000001008080000
Wavelet Hash:33331b1bc0c0fcfc
Color Hash:#784f3a

Other Hashes

Crop Resistant:0000001008080000

Scan History

Scan history not available

Unable to load historical scan data