Security Scan Report: ip-geolocation.whoisxmlapi.com

Site favicon
Submitted: Jan 10, 2026, 10:45:04 AMCompleted: Jan 10, 2026, 10:47:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 29 IPs in 4 countries across 35 domains to perform 113 HTTP transactions. The main domain is ip-geolocation.whoisxmlapi.com and was registered NaN years ago.

Submitted URL: https://ip-geolocation.whoisxmlapi.com

The Cisco Umbrella rank of the primary domain is #195,236 of the top 1 million websites

AI Security Verdict

Safe Website

Confidence: 95%

0
Risk Score

No security concerns detected; site appears legitimate.

Safety Factors
Long-established domain (>16 years)
Minimal risk category from domain age analysis
No suspicious forms or content
Domain age information unavailable

Details

Page Title

IP Geolocation | Find someone’s IP address location | WhoisXML API

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(85%)

Domain Information

The domain name 'ip-geolocation.whoisxmlapi.com' uses the commercial generic top-level domain (.com) and includes subdomain 'ip-geolocation'. The registrable portion 'whoisxmlapi' spans 11 characters with four vowels and seven consonants. Tokenizing the label suggests four words: who, is, xml, api. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ip-geolocation.whoisxmlapi.com

Page Load Overview

47.34s
Total Load Time
130
HTTP Requests
41
Domains
987 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:28,066 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software85% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
85%
documentation technical
46%
government public service
27%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
18142.251.141.98Sweden
4172.64.148.115United States
AS13335CLOUDFLARENET
4104.17.128.172United States
AS13335CLOUDFLARENET
4104.16.109.254Italy
4104.17.24.14United States
AS13335CLOUDFLARENET
4104.19.147.8Unknown
4104.16.50.78Unknown
4104.16.160.168United States
AS13335CLOUDFLARENET
4104.17.91.187United States
AS13335CLOUDFLARENET
4104.18.37.212United States
AS13335CLOUDFLARENET
13029--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14E74F9A6D5F011270AA384A5A5E1670D7E23A117CED20D84F6AC8388EFCBED9CD3355D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:vXgAWfsWGWpKLvTE3uwEq1MReBDJJu3Us9J2ajRGT0SC0YNBR6p:IAKsIpITE3uwEq1MReBDJJu3Us9JOIf6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:351572:EBn0ECEwSAAEAARgMSZFxAdSBUHyIggDS9IpNiwWgFQnjQIoZNJgEw0okmRQDPKEgBobJEIIGCAi6CVCUYEACKgIQWLGgqgE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff000c0e0c00ffff
Perceptual Hash:9213ec6992b966d3
Difference Hash:11f8d8fcd8f83e06
Wavelet Hash:ff000c0e0e00ffff
Color Hash:#bf4093

Scan History

Scan history not available

Unable to load historical scan data