Security Scan Report: python.bj-xzh.com

Submitted: Nov 22, 2025, 5:52:03 AMCompleted: Nov 22, 2025, 5:53:19 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 1 domain to perform 6 HTTP transactions. The main domain is python.bj-xzh.com and was registered NaN years ago.

Submitted URL: https://python.bj-xzh.com/?token=NCt02BJ5smXqwyVXMB39gzajhAb

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

Hidden password form on an unranked domain indicates phishing risk.

Risk Factors
Credential harvesting form collecting passwords
Hidden password field (obfuscation technique)
Unranked domain hosting a login form
Domain age information unavailable

Details

Page Title

申请中心

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

government public service

(78%)

Domain Information

Domain 'python.bj-xzh.com' uses the commercial generic top-level domain (.com), featuring subdomain 'python'. The registrable portion 'bj-xzh' spans 6 characters holding 0 vowels versus five consonants, plus 1 hyphen. Word splitting yields three words: bj, x, zh. Average segment length settles at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://python.bj-xzh.com/?token=NCt02BJ5smXqwyVXMB39gzajhAb

Page Load Overview

0.68s
Total Load Time
6
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:740 chars
Detector Agreement:50%

Website Classification

Primary Category

government public service78% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
78%
corporate business
75%
technology software
75%
cryptocurrency blockchain
75%
documentation technical
73%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6188.114.97.3United States
AS13335CLOUDFLARENET
3188.114.96.3United States
AS13335CLOUDFLARENET
12a06:98c1:3120::3United States
AS13335CLOUDFLARENET
12a06:98c1:3121::3United States
AS13335CLOUDFLARENET
64--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D8E2729665F309A2642BE4F66FD7970636A49003C40DCD143FAC179C4F8ADC1FA6378A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ga/zlXHLdiiilv9mR/Q1KH3cIW0CX4yPUTh8rqZN2vlxpRJeOOBNzPiCjw7JgwWT:pXLeTiVOWRPJeW3SYg4WV2/2hPE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31139:g4CYYxcGQiNBqjGEJDhBCIXAADaFp0VjCkpLaoYSTkQAihNGGEEgaUDAeKCwqhSCGMAgQACOE/YFJcciCIREqtQigGlwsxA6

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data