Security Scan Report: ai123h.xyz

Submitted: Apr 4, 2026, 6:50:26 AMCompleted: Apr 4, 2026, 6:51:48 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 2 countries across 3 domains to perform 2 HTTP transactions. The main domain is ai123h.xyz and was registered NaN years ago.

Submitted URL: https://ai123h.xyz/

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

The site impersonates Telegram on a brand‑new, unranked domain and is likely a phishing page.

Risk Factors
Brand impersonation (Telegram) on a non‑official domain
Newly registered domain (<7 days old)
Unranked domain with no reputation
Phishing QR‑code login prompt
Domain‑brand mismatch
Domain age information unavailable

Details

Page Title

Secure Messenger

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(50%)

Domain Information

Domain 'ai123h.xyz' uses the open generic top-level domain (.xyz) without a subdomain. Count 6 characters in 'ai123h' containing two vowels alongside one consonant; bonus characters include three digits. Breaking it apart gives 4 words: a, i, 123, h. Expect 1 character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ai123h.xyz/

Page Load Overview

1.61s
Total Load Time
26
HTTP Requests
3
Domains
301 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:235 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13216.198.79.131United States
AS16509Amazon.com, Inc.
13149.154.167.99Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
262--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AB5398A49DD85B298E08D78EC5DF1DEC1089C1C68908805FBB757AA7867CD34ACBC397

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:4dsf5iNk/KO2inClsaJRABo/CtQtqtLzy:YsxiNk/KO2inClsaJB/CtQtqtLzy

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:61978:RU4yLgEABDEI0CEkhIK4MEIDFgWk1AIiAgE3hEJhIAAWNjhB4oAXDSfBhxcCOIhHCMI6cxoRA4m4JBwSAEgrkCBDWArEeSAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7e7ffffff
Perceptual Hash:b33366899999cccc
Difference Hash:0c4d4d080c000000
Wavelet Hash:00000404233b0f0f
Color Hash:#e0946c

Other Hashes

Crop Resistant:0c4d4d080c000000

Scan History

Scan history not available

Unable to load historical scan data