Security Scan Report: haterman01-email-fix-server0978u7y65.mdbgo.io

Submitted: Nov 6, 2025, 2:06:59 PMCompleted: Nov 6, 2025, 2:08:25 PMpubliccompleted
Loading additional data...

Summary

This website contacted 19 IPs in 3 countries across 8 domains to perform 13 HTTP transactions. The main domain is haterman01-email-fix-server0978u7y65.mdbgo.io.

Submitted URL: https://haterman01-email-fix-server0978u7y65.mdbgo.io/[email protected]

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

Phishing login page on a suspicious, unranked domain

Risk Factors
Credential harvesting form on a low‑reputation, unranked domain
Brand impersonation on a domain not associated with the brand
New or unknown domain age increases suspicion
Domain age information unavailable

Details

Page Title

Baroken - MAIL SYSTEM Sign in to continue

Scan Type

public

Language

🇺🇸

English

(65% confidence)

Category

unknown

(0%)

Domain Information

Domain 'haterman01-email-fix-server0978u7y65.mdbgo.io' uses the British Indian Ocean Territory country-code top-level domain (.io) and includes subdomain 'haterman01-email-fix-server0978u7y65'. Count 5 characters in 'mdbgo' with 1 vowel and four consonants. Word splitting yields three words: m, db, go. The median word length lands at two characters. Most frequently, 'm' shows up in Chinese (Pinyin). You may catch it in English and Chinese (Traditional) as well. Net impression: Chinese (Pinyin) phrase.

Screenshot

Security scan screenshot of https://haterman01-email-fix-server0978u7y65.mdbgo.io/index.html?e=info@baroken.com

Page Load Overview

35.18s
Total Load Time
13
HTTP Requests
8
Domains
317 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:65%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:65%
Script Type:Latin
Text Length:143 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13104.17.25.14United States
AS13335CLOUDFLARENET
0142.250.185.163United States
AS15169GOOGLE
0146.75.120.193Frankfurt am Main, Hesse, Germany
AS54113FASTLY
0104.16.174.226United States
AS13335CLOUDFLARENET
0142.250.186.164United States
AS15169GOOGLE
054.210.238.130Ashburn, Virginia, United States
AS14618AMAZON-AES
0142.250.185.202United States
AS15169GOOGLE
093.105.88.216Wroclaw, Lower Silesia, Poland
AS50606Horyzont Technologie Internetowe sp.z.o.o.
0142.250.186.74United States
AS15169GOOGLE
02606:4700::6810:aee2United States
AS13335CLOUDFLARENET
1319--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12232C72190F818323233C4B826C656893A349427DB534F6C79BC6AED9FD6D97987378C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:mGC82saWFSRXKbZjcM0ptOBLZodAjDWoWQuwklJx0Q7u0Dr+aC4sdcjReaj:C82xWFWGdXWtNd6Qa0DL8cjReaj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11267:NiogYSAooKSMFDPgkAAGQehZBehBXBBCUiMDwMCsQFpDI0CEGDEWkABAjQACEROAwgxAR5C3ymRUcMJASABKGDlmwSGhDIbQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data