Security Scan Report: jtx.vxf.mybluehost.me

Submitted: Nov 5, 2025, 12:55:34 AMCompleted: Nov 5, 2025, 12:56:23 AMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 2 countries across 3 domains to perform 38 HTTP transactions. The main domain is jtx.vxf.mybluehost.me.

Submitted URL: https://jtx.vxf.mybluehost.me/pe/tem/BILLING/page/online.php

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Confirmed phishing site impersonating Netflix; do not enter credentials.

Risk Factors
Brand impersonation (Netflix) on an unranked, likely newly registered domain
Credential harvesting form collecting email/phone and password
Password field without a clearly linked username field
Domain age appears to be 0 days (very new)
Unranked domain (not in Cisco Umbrella top 1M) used for phishing
Domain age information unavailable

Details

Page Title

503 Service Unavailable

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

adult content

(38%)

Domain Information

The domain 'jtx.vxf.mybluehost.me' uses the Montenegrin country-code top-level domain (.me) and includes subdomain 'jtx.vxf'. The core label 'mybluehost' covers 10 characters holding 3 vowels versus 7 consonants. Segmentation suggests 3 words: my, blue, host. Median word length comes out to 4 characters. 'my' most strongly signals Afrikaans. Secondary signals appear in English and Chinese (Pinyin). Taken together, it feels Afrikaans.

Screenshot

Security scan screenshot of https://jtx.vxf.mybluehost.me/pe/tem/BILLING/page/online.php

Page Load Overview

22.18s
Total Load Time
38
HTTP Requests
3
Domains
457 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,199 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content38% confidence
Type: static
Method: ml+structural

All Detected Categories

adult content
38%
finance banking
35%
gambling betting
33%
technology software
29%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
850.6.34.31Frankfurt am Main, Hesse, Germany
AS31898ORACLE-BMC-31898
6185.15.59.240United States
AS14907WIKIMEDIA
6142.250.185.170United States
AS15169GOOGLE
62a00:1450:4001:827::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
6142.250.181.234United States
AS15169GOOGLE
62a02:ec80:300:ed1a::2:bUnited States
AS14907WIKIMEDIA
386--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T184E068CF5195303354A2D3586C937794B702728C167070B817E91C7F50DBC5A5A9FB61

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:qzxwMRpNEr6VXjHpnK20QIjp/BAZFyKm5Jj6BCQ1EHcLZYpKLjsKtgsg93wzRJz:kx1RpNRBpnKBQIl/BAZFEjICQ+8YpKjl

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:2f253a5290d185580a3889a758243519

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f0fffffffffffff
Perceptual Hash:9b1b0f0f0f0707c7
Difference Hash:f030000000000000
Wavelet Hash:00f0f0f0f0f0f0f0
Color Hash:#539aac

Other Hashes

Crop Resistant:f030000000000000

Scan History

Scan history not available

Unable to load historical scan data