thorkildkristensen.sbs
172.67.190.17AS13335 · USa fake verification gate that no challenge provider is behind, whose form collects nothing from the visitor and instead submits 10 hidden fields measuring them, one of them a honeypot the visitor cannot see
- Browser Analysissuspicious
- Content Inspectionsuspicious
- Threat Intelligenceclean
- Network & Hostingclean
- Related Infrastructureclean
- Domain Intelligenceunknown
- TLS Fingerprintunknown
- Lexical Url Heuristicunknown
Be careful — warning signs found
AutomatedThis site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.
What to do
Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.
"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.
Findings
Strongest firstOur Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.
Success
SHA-256 9a00edd816326e946014a7bb2398413fc5d20c44b26bc0cbce13c0eaed33ed2e
The page prints a verification prompt, but no challenge provider is behind it and its form asks the visitor for nothing: every field is hidden state about whoever arrived (whether scripting is on, a mouse-movement count, how long they took, the device type) or a honeypot they cannot see. A page that SCORES its visitor instead of challenging them is deciding who is allowed to reach what is behind it — the shape of a phishing kit's doorway.
Analyst noteOpen the page's own script: this kit's is a single eval(atob(...)) that starts at a score of 70 and subtracts for navigator.webdriver and for 'headless' in the user agent. A genuine challenge is served by its provider and never scores you in page script. If an address is named above, treat it as the targeted recipient and check whether that mailbox got the message.
Infrastructure
- IP
- 172.67.190.17CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
- TLS
- CN=WE1, O=Google Trust Services, C=US · expires Nov 29, 2026
- Redirects
- 0 hops · / → /
WHOIS
- Registrar
- Dynadot Inc
- Created
- Aug 28, 2026
- Expires
- Aug 28, 2027
- Nameservers
- ajay.ns.cloudflare.comkayleigh.ns.cloudflare.com
Hashes & fingerprints
Page capture
LiveTitle “Human Verification”
Engines
8 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- Human Verification
- Load
- 11.08 s · 1 requests