Security Scan Report: l.ead.me

Redirected to:
https://teamserv.jdevcloud.com/swiss/d/sign.php
Site favicon
Submitted: Nov 23, 2025, 5:08:56 AMCompleted: Nov 23, 2025, 5:09:38 AMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 3 countries across 4 domains to perform 11 HTTP transactions. The main domain is teamserv.jdevcloud.com and was registered NaN years ago.

Submitted URL: https://l.ead.me/bgT5ll

Effective URL: https://teamserv.jdevcloud.com/swiss/d/sign.phpRedirected

The Cisco Umbrella rank of the primary domain is #530,383 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing site impersonating SwissPass to harvest credentials

Risk Factors
Brand impersonation (SwissPass) on an unrelated, low‑rank domain
Hidden password field in HTML
Credential collection form with password fields
Multiple redirects to a suspicious subdomain
Domain age information unavailable

Details

Page Title

SwissPass

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

technology software

(29%)

Domain Information

Domain 'l.ead.me' uses the Montenegrin country-code top-level domain (.me), featuring subdomain 'l'. The second-level label 'ead' is 3 characters long holding 2 vowels versus 1 consonant. Tokenizing the label suggests 1 word: ead. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://l.ead.me/bgT5ll

Page Load Overview

1.03s
Total Load Time
11
HTTP Requests
4
Domains
376 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de-ch
Text Length:924 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software29% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
29%
social_media
25%
corporate
25%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8185.187.254.203Sweden
AS29024Hostek AB
1141.101.90.104United States
AS13335CLOUDFLARENET
13.73.88.115Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
13.174.46.6United States
AS16509AMAZON-02
018.157.194.212Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
03.174.46.58United States
AS16509AMAZON-02
0141.101.90.106United States
AS13335CLOUDFLARENET
02a06:98c1:3200::90:81United States
AS13335CLOUDFLARENET
03.174.46.27United States
AS16509AMAZON-02
0141.101.90.107United States
AS13335CLOUDFLARENET
1116--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11BB2C62190F6193B211780D96BEB7F126EA2C703C5868418F6FE5BCD4FDAD42DA4366C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:nnJEsOpJdCYisVZfV9Phia/yEjPyZ5rxnRy8cMnRqC0gclS4KSW4KSMSNTgk+FQ7:nJcnXXljInRy8cMnRqC0gcl5zPq1m

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23663:TSJkABEsXRU5BSBQgEMOICCSwNWLEhDLAI4RzIpYiPHgJhAKGnlgBCJQUBPrGRxLADE2cEE0EBsEQCSiWLsicgoAAICFXEAM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e5e1e1e1e1e1e1ff
Perceptual Hash:e3379c62960e9d8c
Difference Hash:0d4f534d4d4d4595
Wavelet Hash:e5e0a0a0e1e1e1ff
Color Hash:#9ad279

Scan History

Scan history not available

Unable to load historical scan data