Security Scan Report: ph.whitebit.com

Redirected to:
https://ph.whitebit.com/login
Submitted: Apr 16, 2026, 3:37:45 AMCompleted: Apr 16, 2026, 3:38:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 1 HTTP transaction. The main domain is ph.whitebit.com and was registered NaN years ago.

Submitted URL: https://ph.whitebit.com

Effective URL: https://ph.whitebit.com/loginRedirected

The Cisco Umbrella rank of the primary domain is #304,252 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 92%

5
Risk Score

The site impersonates PostHog login, collects credentials on a low‑ranked, unrelated domain; high‑risk phishing scam.

Risk Factors
Brand impersonation (PostHog) on unrelated domain
Credential‑stealing login form
Low domain ranking for claimed brand
Highly obfuscated JavaScript
Mismatch between brand and hosting domain
Safety Factors
Domain age > 17 years (well‑established)
No malicious Indicators of Compromise detected
No network IDS alerts
No cross‑origin credential exfiltration
Established domain (6427 days old) with no strong malicious indicators — risk clamped from 9 to 5
Domain age information unavailable

Details

Page Title

Login • PostHog

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

adult content

(44%)

Domain Information

Domain 'ph.whitebit.com' uses the commercial generic top-level domain (.com) with subdomain 'ph'. The second-level label 'whitebit' is 8 characters long with 3 vowels and five consonants. Breaking it apart gives 2 words: white, bit. Average segment length settles at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ph.whitebit.com

Page Load Overview

0.70s
Total Load Time
46
HTTP Requests
1
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:101 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content44% confidence
Type: webapp
Method: ml+structural

All Detected Categories

adult content
44%
news media journalism
36%
entertainment media
36%
forum community discussion
27%
government public service
26%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1618.66.92.11United States
15172.64.155.125United States
AS13335Cloudflare, Inc.
1554.90.36.212United States
463--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E7231F42A4A2CC3E7031A982B1BD8D96D92594951ACC0F44B84EB2D9F30C5D67B375FF

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:xGoIJ2WGKQ7kb5Hlh1itFSSZ6K+Q8DfmJV4lRknx/R:xGoIoyQI9HlhYFSSZ6Kd8Dfc4lR6x/R

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:49767:QJocAmMZRQoZSQinjM0ICVCOkAAkCswUBACRqOgABJqCrEQwAAUoAt4nKYAgsMIKREgOANAxDIAheQDmMqoEMJIwTgi4ERtg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfc3cfffff
Perceptual Hash:b1c6ce3931c6ce31
Difference Hash:08264c9c9e996610
Wavelet Hash:3c3c140c030f0f0f
Color Hash:#783a6b

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data