Security Scan Report: candidat.hosted.phplist.com

Redirected to: https://didoron.com.ar/cdkm/markez/?20252025teamitalie

Submitted: Dec 9, 2025, 9:29:25 AMCompleted: Dec 9, 2025, 9:29:50 AMpubliccompleted
Loading additional data...

Summary

This website contacted 11 IPs in 5 countries across 5 domains to perform 20 HTTP transactions. The main domain is didoron.com.ar.

Submitted URL: https://candidat.hosted.phplist.com/

Effective URL: https://didoron.com.ar/cdkm/markez/?20252025teamitalieRedirected

The Cisco Umbrella rank of the primary domain is #213,110 of the top 1 million websites

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Confirmed scam: payment phishing on a brand‑new, low‑reputation domain.

Risk Factors
Collection of payment information on a newly registered, low‑ranking domain
Domain age less than 7 days with a payment form (triggers CONFIRMED_SCAM rule)
Low reputation ranking (outside top 10k) amplifies suspicion
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇮🇹

Italian

(80% confidence)

Category

e-commerce

(40%)

Domain Information

The domain 'candidat.hosted.phplist.com' uses the commercial generic top-level domain (.com), featuring subdomain 'candidat.hosted'. The core label 'phplist' covers 7 characters holding 1 vowel versus 6 consonants. It segments into 2 words: php, list. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://candidat.hosted.phplist.com/

Page Load Overview

2.86s
Total Load Time
20
HTTP Requests
5
Domains
100 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:it
Text Length:462 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce40% confidence
Type: dynamic
Method: structural

All Detected Categories

e-commerce
40%

Detected Features

Payment

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10149.154.167.220London, England, United Kingdom
AS62041Telegram Messenger Inc
13.167.226.45United States
AS16509AMAZON-02
1200.58.110.220Rosario, Santa Fe, Argentina
AS27823Dattatec.com
1142.250.185.234United States
AS15169GOOGLE
145.33.29.14Richardson, Texas, United States
AS63949Akamai Connected Cloud
12800:6c0:2::8Buenos Aires, Buenos Aires F.D., Argentina
AS27823Dattatec.com
13.167.226.172United States
AS16509AMAZON-02
13.167.226.71United States
AS16509AMAZON-02
12a00:1450:4001:82b::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12001:67c:4e8:f004::9Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
2011--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12A22DEA050F1497B00FB98D96A656E1A9ED1E203CD27014AB7EC4FE60FDBD4BCE53618

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:fD+Vtu9tCMf7wF/ExrqEPEW6OKO6i76tlPYLFWe/t96sPajfjMscmJ:fD+Vc9tzf7jP6je/rXajft

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10899:iAmMUQn0E6TEXgEAjhSGKA+AOMEAFRSgzOIFgUEooqBGmMCIQ0ABUTAYEKADTAEhCkqBBOAAyAhbCYIY7TVICbUCFBQBVEkY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data