Security Scan Report: www.bqzl36.vip

Redirected to:
https://www.xav9nz.vip:6003/register48967?i_code=73104968
Site favicon
Submitted: Sep 20, 2026, 8:47:33 PMCompleted: Sep 20, 2026, 8:48:03 PMpubliccompleted

This website contacted 3 IPs in 3 countries across 3 domains to perform 34 HTTP transactions. The main domain is xav9nz.vip and was registered 2 months ago.

Submitted URL: https://www.bqzl36.vip

Effective URL:

https://www.xav9nz.vip:6003/register48967?i_code=73104968
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Fake gambling/betting portal impersonating Kaiyun Sports (开云体育) and Real Madrid, using a cross-domain redirect to a registration form capturing credentials. High risk — avoid.

Risk Factors (5)
Impersonation of a known gambling brand (开云体育 / Kaiyun Sports) and Real Madrid on non-official domains
Credential-capturing registration form with two password fields
Cross-domain redirect chain used to obscure the destination host
Threat-intel match naming the Formbook malware family on the entry domain
No domain reputation; single-source unverified abuse and malware indicators
Domain age information unavailable

Details

Page Title

乐部官方区域合作伙伴    开云体育官网-皇家马德里足球俱

Scan Type

public

Domain Name Analysis

You're looking at domain 'www.bqzl36.vip' on the .vip top-level domain, featuring subdomain 'www'. Its registrable label 'bqzl36' stretches across 6 characters with 0 vowels and 4 consonants, along with two digits. Word splitting yields three words: bq, zl, 36. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.bqzl36.vip

Page Load Overview

11.18s
Total Load Time
929 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Text Length:126 chars
Detector Agreement:50%

Website Classification

Primary Category

gambling betting43% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
43%
government public service
33%
adult content
32%
blog personal website
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12172.65.242.166Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11154.220.10.112Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
1143.243.240.205Hong Kong
AS153494XRUI TECHNOLOGY LIMITED
343--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T164C23C334909B8730D363C9AE5E66A4E1C0CD21AD56346C4F2ADF6EAD6DEF0A5C0F494

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:dEhxQCp8MZTMqtah6mpYZxMU76gGBtS6x9flMjURZsVuSbxfcRBx2OcRBq3hcROP:dEhxQCp8MZThmqdOTBtSk99MjFVuA+D9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26607:BVJikFApESITaBBJIIxjUPCBAXRQBMBAhyAaBJX0khSGADQYIBkLAJ6AaeCKBZQAgHM0jEhKEAukwAAhwANAJtADk0gYZzPG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff1818180000
Perceptual Hash:cc8cb3069e969db1
Difference Hash:e0f0b2b2b232f0e0
Wavelet Hash:ffffff1818181800
Color Hash:#87bac5

Other Hashes

Crop Resistant:e0f0b2b2b232f0e0

Scan History

Scan history not available

Unable to load historical scan data