Security Scan Report: dwp.signals.crowdclean.co

Redirected to:
https://d25txf7jq0jjmz.cloudfront.net/auth/login/
Submitted: Sep 1, 2026, 12:58:42 PMCompleted: Sep 1, 2026, 12:59:59 PMpubliccompleted

This website contacted 9 IPs in 1 country across 4 domains to perform 15 HTTP transactions. The main domain is d25txf7jq0jjmz.cloudfront.net and was registered 18 years ago.

Submitted URL: https://dwp.signals.crowdclean.co

Effective URL:

https://d25txf7jq0jjmz.cloudfront.net/auth/login/
Redirected

The Cisco Umbrella rank of the primary domain is #488,187 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 72%

5
Risk Score

The page hosts a standard login form for its own brand on an unknown‑age, low‑rank domain; no malicious indicators were found, resulting in a moderate risk rating.

Risk Factors (2)
Credential collection form on an unknown‑age, low‑rank domain
Cross‑origin form submission to a different domain (cloudfront.net)
Safety Factors (4)
No malicious IoC matches
No JavaScript malware detections
No network IDS alerts
Page appears to be a legitimate login for the "Signals Gateway" service
Domain age information unavailable

Details

Page Title

Login

Scan Type

public

Domain Name Analysis

Domain 'dwp.signals.crowdclean.co' uses the Colombian country-code top-level domain (.co) and includes subdomain 'dwp.signals'. The second-level label 'crowdclean' is 10 characters long containing 3 vowels alongside seven consonants. It segments into 2 words: crowd, clean. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dwp.signals.crowdclean.co

Page Load Overview

2.55s
Total Load Time
534 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:171 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software43% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
43%
corporate business
36%
finance banking
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
752.26.74.17Aws · CLOUDBoardman, Oregon, United States
AS16509Amazon.com, Inc.
113.35.58.123Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1142.251.13.95Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
154.184.19.112Aws · CLOUDBoardman, Oregon, United States
AS16509Amazon.com, Inc.
113.35.58.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
113.35.58.114Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
113.35.58.83Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
159--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D941DA4BDC00C11497508A96AB73F23C9C81ED8D9951F9D0F8A640ACC06479CEC6B821

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:ThxH0xaITY28YcS8Wb9QfRD07xkzTvJOIIB0bPb5T2RpMR+m:ThxH09Y2iC9QfRD4xk5IlXMR/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2085:AAhAAABKkAAogAJAUAEAAAABAAAAIAAAmAAIBgAAEAAAAAACEBCEAIAAABACDIgAAhAAABAAQAAABAAAhCABUABFCKACIAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff9f9fff0f1fff9f
Perceptual Hash:9ec2e11dc3e13c1e
Difference Hash:0020300030300020
Wavelet Hash:f09090000000f090
Color Hash:#5340bf

Other Hashes

Crop Resistant:0020300030300020

Scan History

Scan history not available

Unable to load historical scan data