Security Scan Report: stormvenomcitadel.top

Submitted: Sep 13, 2026, 2:47:45 AMCompleted: Sep 13, 2026, 2:48:08 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Primary domain is flagged as magecart malware (single-source ThreatFox) on an 85-day-old .top domain with hostile-TLD IDS alerts; currently only a Cloudflare 521 error page. Treat as high risk.

Risk Factors
Single-source ThreatFox report tagging the primary domain as magecart (credit-card skimming malware)
Recently registered domain (85 days) with no reputation ranking
.top TLD flagged by network IDS as likely hostile
Origin server down (521) preventing full page-content verification
Domain age information unavailable

Details

Page Title

stormvenomcitadel.top | 521: Web server is down

Scan Type

public

Domain Name Analysis

The domain name 'stormvenomcitadel.top' uses the .top top-level domain without a subdomain. The second-level label 'stormvenomcitadel' is 17 characters long holding six vowels versus 11 consonants. It segments into three words: storm, venom, citadel. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://stormvenomcitadel.top

Page Load Overview

3.04s
Total Load Time
23 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:698 chars
Detector Agreement:67%

Website Classification

Primary Category

documentation technical77% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
77%
technology software
70%
government public service
54%
cryptocurrency blockchain
50%
news media journalism
45%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.21.70.144Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.136.187Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14AE17775B1B512770093C1A23696EB6979E4C213CBEF4594B3DDC2632F9EE82D903250

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:ljHjCIju3Da/D2KUujG4Fh8/G4FOA424Fu+skKmk2OLwmNnwL5JxFR63FaQxJ:ljHjDjuza/Cqje8AVO/Q85JxFo3weJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6976:WABBVyBoFIAKPGiISIQIAR7BCAJIAaJ8MFpFIYEIJpAVQOAmHCcAUAFYBqsEkAFYMARghBNimpMgIChIUCiAFGhQEIJBAVI4

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c70000d7f7ffff
Perceptual Hash:b4389abc9a676531
Difference Hash:1c3e8e8a3406061c
Wavelet Hash:c7000000d7f3f7ff
Color Hash:#40bf64

Other Hashes

Crop Resistant:1c3e8e8a3406061c

Scan History

Scan history not available

Unable to load historical scan data