Security Scan Report: novo.clickmed.pt

Submitted: Nov 13, 2025, 11:52:08 AMCompleted: Nov 13, 2025, 11:53:02 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 2 domains to perform 6 HTTP transactions. The main domain is novo.clickmed.pt.

Submitted URL: https://novo.clickmed.pt/domini/

AI Security Verdict

High Risk

Confidence: 88%

7
Risk Score

High‑risk phishing site impersonating Aruba.it; do not trust.

Risk Factors
Brand impersonation (Aruba.it) on a non‑official domain
UNRANKED domain with low reputation
Email collection form that could be used for credential harvesting
Domain age information unavailable

Details

Page Title

One moment, please...

Scan Type

public

Language

🇮🇹

Italian

(80% confidence)

Category

phishing/scam

(40%)

Domain Information

The domain name 'novo.clickmed.pt' uses the Portuguese country-code top-level domain (.pt), featuring subdomain 'novo'. The core label 'clickmed' covers 8 characters holding two vowels versus 6 consonants. Tokenizing the label suggests two words: click, med. Average segment length settles at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://novo.clickmed.pt/domini/

Page Load Overview

29.97s
Total Load Time
6
HTTP Requests
2
Domains
139 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:it
Text Length:453 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing/scam40% confidence
Type: static
Method: structural

All Detected Categories

phishing/scam
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1104.17.25.14United States
AS13335CLOUDFLARENET
1185.12.116.231Portugal
AS33876Dominios, S.A.
12606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
12606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
1104.17.24.14United States
AS13335CLOUDFLARENET
65--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D32069CEE906270F21703DA77EF2D19262C60E72048C458F54C6DD87F473CD8666B2A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:CXHNsGeTHQpD+da6+8QPUV7lrDyjFrxzjfpcBy20Yc7mvMRunoh:CXX+/zV7SFZjf0x0nSUkW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11512:igAHKBQhgKITiisBygRAgCNUkCu7QRIrHgHSrGka4hBHAKJAPxiTECB3QtKBPInA6RgABCJC0BCQiFAM4AIFNwBXAhQIggBN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff81ffffffff
Perceptual Hash:bf2fc0c03f3fc0c0
Difference Hash:0000012301000000
Wavelet Hash:ffffff8100000000
Color Hash:#d27992

Other Hashes

Crop Resistant:0000012301000000

Scan History

Scan history not available

Unable to load historical scan data