Security Scan Report: payment-better.com

Submitted: Dec 20, 2025, 10:32:21 AMCompleted: Dec 20, 2025, 10:32:38 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 1 domain to perform 13 HTTP transactions. The main domain is payment-better.com and was registered NaN years ago.

Submitted URL: https://payment-better.com/index.php?m=User&a=signup

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site harvesting credentials from a brand‑less, brand‑new domain.

Risk Factors
Newly registered domain (<7 days) with a login form
Password field without accompanying username/email field
Potential hidden password field (placeholder in Thai language)
Unranked, brand‑less domain used for credential collection
Domain age information unavailable

Details

Page Title

SIGNUP

Scan Type

public

Language

🇹🇭

TH

(60% confidence)

Category

unknown

(0%)

Domain Information

Domain 'payment-better.com' uses the commercial generic top-level domain (.com) with no subdomain. Count 14 characters in 'payment-better' with four vowels and nine consonants, along with 1 hyphen. Tokenizing the label suggests 2 words: payment, better. The median word length lands at 6.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://payment-better.com/index.php?m=User&a=signup

Page Load Overview

2.84s
Total Load Time
13
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇹🇭Thai
Code: th
Confidence:60%
Script:Unknown
Direction:ltr

Detection Details

Language Code:th
Detection Confidence:60%
Script Type:Unknown
HTML Lang Attribute:en
Text Length:44 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as th

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.21.53.168United States
AS13335CLOUDFLARENET
6172.67.215.171United States
AS13335CLOUDFLARENET
132--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19E629552E74D0D0B711520701864BBC9712E99339A099CE8BEFD194CBFE6F199237DB2

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:in4YkcqXkXS9BPdz22eePNiDiCiz8wJJCQ:kYcag6VK9ekmrzFJkQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:14843:LFiDpAcNFXAAQU0AAOFARi4gROIsIHZkSIjyAoAKxgnNcMmxiKFn7oAYjlYEBIkIRhDMAIpRokg4BygGOipgQIKIAAhTAIQE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:5918181818180000
Perceptual Hash:ccd833cccc3332e6
Difference Hash:b53232b2b2321008
Wavelet Hash:dfdb18183c3c3830
Color Hash:#87c5a9

Scan History

Scan history not available

Unable to load historical scan data