URL Scan
The only capture we hold is a challenge page, not the service. It is kept for evidence but is not shown here as if it were the site. View the raw capture.
URL and website scanner - urlscan.io
Website scanner for suspicious and malicious URLs
urlscan.io Home Search Live API Blog Docs Pricing Login urlscan.io A sandbox for the web URL Triage Public Scan Options Recent scans Updates every 10s - Last update: 19:57:45 URL Age Size IPs whm.www.www.admin.www.api.as.152-53-37-155.plesk.page/ 11 seconds 2 MB 119 32 6 bielefeldspielbank.com.de/ 12 seconds 651 KB 34 1 1 personaltrainer-ingo-gaube.de/ 14 seconds 4 MB 20 3 2 astaging.xwold.rqpsnotexistsihgfed495639f7-a0b4-4c61-ba1b-8056f83ce0cf.mutgicon... 14 seconds 57 KB 3 1 1 masoswiss.com/ 16 seconds 1010 KB 77 9 4 www.festumvretensis.com.vuxenpedagogik.com/ 18 seconds 2 MB 12 2 1…
Page author: urlscan.io
| When | Status | HTTP | Response | Bytes | Via |
|---|---|---|---|---|---|
| 4m ago | Alive content moved | 200 | 30 ms | 44,865 | chrome-stealth |
| 1h ago | Alive content moved | 200 | 27 ms | 44,865 | chrome-stealth |
| 2h ago | Alive content moved | 200 | 30 ms | 44,865 | chrome-stealth |
| 4h ago | Alive content moved | 200 | 28 ms | 44,865 | chrome-stealth |
| 6h ago | Alive | 200 | 31 ms | 44,865 | chrome-stealth |
- Csp
- Raw
default-src 'self' data: urlscan.io sentry.urlscan.io; script-src 'self' data: developers.google.com www.google.com www.gstatic.com urlscan.io sentry.urlscan.io; style-src 'self' fonts.googleapis.com www.google.com cdnjs.cloudflare.com urlscan.io; img-src * data:; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com urlscan.io; child-src 'self'; frame-src https://www.google.com/recaptcha/; form-action 'self'; connect-src 'self' api.checklyhq.com sentry.urlscan.io urlscan.io *.urlscan.io https://www.google.com/recaptcha/; upgrade-insecure-requests; frame-ancestors 'none';- Directives
- Default src
- 'self'data:urlscan.iosentry.urlscan.io
- Script src
- 'self'data:developers.google.comwww.google.comwww.gstatic.comurlscan.iosentry.urlscan.io
- Style src
- 'self'fonts.googleapis.comwww.google.comcdnjs.cloudflare.comurlscan.io
- Img src
- *data:
- Font src
- 'self'fonts.gstatic.comcdnjs.cloudflare.comurlscan.io
- Child src
- 'self'
- Frame src
- https://www.google.com/recaptcha/
- Form action
- 'self'
- Connect src
- 'self'api.checklyhq.comsentry.urlscan.iourlscan.io*.urlscan.iohttps://www.google.com/recaptcha/
- Frame ancestors
- 'none'
- Unsafe inline
- no
- Unsafe eval
- no
- Hsts
- Max age
63072000- Include subdomains
- yes
- Preload
- yes
- X frame options
DENY- X content type options
nosniff- Referrer policy
same-origin- Cross origin
- X xss protection
0- Cookies
- Count
0- Secure
0- Httponly
0- Samesite
0
- Score
80- Missing
- permissions_policycoopcoepcorp
- Protocol
TLS 1.3- Cipher
AES_128_GCM- Key exchange group
X25519MLKEM768- Signature algorithm
1027- Subject
urlscan.io- Issuer
YE2- San
- *.urlscan.com*.urlscan.io*.urlscan.neturlscan.comurlscan.io
- San count
5- Wildcard
- yes
- Valid from
2026-07-06 05:50:13- Valid to
2026-10-04 05:50:12- Days remaining
43- Self signed
- no
- Ct compliance
unknown- Ech
- no
- Server
- Raw
nginx- Name
nginx- Family
nginx
- Js
- Name
reCAPTCHA
- Name
Bootstrap
- Protocol
h2
- Detected
- yes
- Kind
recaptcha- Vendor
Google- Label
Google reCAPTCHA- Confidence
100- Signals
- reCAPTCHA api originreCAPTCHA static origing-recaptcha containergrecaptcha global
- Self clearing
- no
- Waited ms
0- Http code
200- Via
chrome-stealth
- Total
0
- Total
0
- Count
1- Kinds
- Search
1
- Has login
- no
- Has search
- yes
- Has upload
- no
- Forms
- Kind
search- Method
post- Action
https://urlscan.io/result/scan/- Inputs
3- Types
- texttextareasubmit
- Password
- no
- File
- no
-
onion_unique
not tracked
onion_unique -
onion_total
not tracked
onion_total -
clearnet_unique
not tracked
clearnet_unique10 -
internal
not tracked
internal26 -
external
not tracked
external10 -
total
not tracked
total42 -
truncated
not tracked
truncated
| Header | Value |
|---|---|
cache-control |
public, max-age=60 |
content-encoding |
gzip |
content-security-policy |
default-src 'self' data: urlscan.io sentry.urlscan.io; script-src 'self' data: developers.google.com www.google.com www.gstatic.com urlscan.io sentry.urlscan.io; style-src 'self' fonts.googleapis.com www.google.com cdnjs.cloudflare.com urlscan.io; img-src * data:; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com urlscan.io; child-src 'self'; frame-src https://www.google.com/recaptcha/; form-action 'self'; connect-src 'self' api.checklyhq.com sentry.urlscan.io urlscan.io *.urlscan.io https://www.google.com/recaptcha/; upgrade-insecure-requests; frame-ancestors 'none'; |
content-type |
text/html; charset=utf-8 |
date |
Fri, 21 Aug 2026 17:57:15 GMT |
etag |
W/"af41-PtKeT94b+1Sk++lyCuVowh3IpJc" |
referrer-policy |
same-origin |
server |
nginx |
strict-transport-security |
max-age=63072000; includeSubdomains; preload |
vary |
Accept-Encoding |
x-content-type-options |
nosniff |
x-frame-options |
DENY |
x-proxy-cache |
HIT |
x-robots-tag |
all |
x-xss-protection |
0 |