ScamLens analyzed 97ee5.catex.at using 90+ threat intelligence sources and assigned a trust score of 88/100, classifying it as safe.
Trust Score: 88/100
Risk Level: Trusted
There is no strongest risk signal at the moment, but that does not automatically clear the case. Continue by checking the actual transaction scenario, company identity, and communication method.
Quick Answer
There is no strongest risk signal at the moment, but that does not automatically clear the case. Continue by checking the actual transaction scenario, company identity, and communication method.
Positive Signals
- + Google Safe Browsing: Safe
- + HTTPS encryption supported
Concerns
- - 2 security sources flagged as suspicious
Score Breakdown
Was this assessment accurate?
97ee5.catex.at looks legitimate
No threat feeds have flagged this domain. Use standard online-safety habits.
- Bookmark the official URLScammers often clone legitimate brands at look-alike domains. A saved bookmark protects you from typos.
- Watch for unexpected payment requestsEven legitimate sites can be hijacked. Treat unsolicited 'urgent payment' prompts as suspicious.
- Verify HTTPS + the exact spellingConfirm the lock icon, and inspect the domain letter-by-letter before entering passwords or card details.
Trust but verify — open this domain on unrelated security services and compare the verdict.
AI Risk Assessment
SafeWhat matters right now
This is better handled as a scenario-verification case, not as a neutral result that automatically clears the domain.
This domain presents a high-risk profile due to confirmed brand impersonation and multiple phishing threat feed alerts. [FACT] The domain matches 'x.com' with 0.8 similarity via subdomain spoofing 5, a hallmark impersonation technique. [FACT] Two independent threat feeds—openphish and phishing_army—have flagged this domain for phishing 2, while 25 of 27 feeds remain clean 3. [INFERENCE] The combination of detected impersonation targeting a major social platform (X/Twitter) alongside corroborating phishing feed flags indicates this is likely a credential harvesting or fraud site designed to deceive users into thinking they're accessing X services. [FACT] Google Safe Browsing is currently clean 1, suggesting this may be newly deployed or not yet indexed by Google's systems. [FACT] The .at TLD carries low abuse risk 4, but this does not mitigate the impersonation and phishing signals.
Recommendation
Do not visit or interact with this domain. Do not enter any credentials. [INFERENCE] If you intended to access X (formerly Twitter), navigate directly to x.com or use official X mobile apps instead of clicking external links. Report this domain to X's trust and safety team and to phishing databases. Consider blocking it at your network or device level.
Sources
- Threat intelligence feeds (2 flagged)Threat intel
openphish (phishing); phishing_army (phishing)
- 25/27 threat feeds responded cleanThreat intel
- TLD risk classification: .at (low risk)Analysis
Based on APWG / Spamhaus / Interisle 2024 abuse rankings
- Brand impersonation: matches "x.com"Analysis
Powered by ScamLens AI· Check sources to verify important claims
Threat-intelligence sources
Checked across 27 sources — 2 flagged this domain
Show source breakdown
Threat-intelligence sources
Checked across 27 sources — 2 flagged this domain
- safe_browsing clean
- urlhaus clean
- cloudflare_radar clean
- cert_transparency clean
- alienvault_otx clean
- phishstats clean
- virustotal clean
- ipqs clean
- abuseipdb clean
- securitytrails clean
- phishdestroy clean
- threatfox clean
- shodan_internetdb clean
- phishtank clean
- urlscan clean
- rdap clean
- maltiverse clean
- dns_security clean
- wanted_domains clean
- darkweb clean
- openphish flagged
- phishing_army flagged
- scam_blocklist clean
- maltrail clean
- crypto_scam_feed clean
- hagezi_tif clean
- red_flag_domains clean
ScamLens aggregates real-time signals from 90+ commercial and open-source threat-intelligence providers including Google Safe Browsing, VirusTotal, PhishTank, URLhaus, ThreatFox, Cloudflare Radar, OTX, IPQS, GoPlus, Honeypot.is, and more. A flagged signal is evidence; the absence of flags is not proof of safety. Use the signals below alongside community reports to decide.
Advanced Scan
Comprehensive data lookup across premium sources
- Website history verification
- Detailed WHOIS information
- Reverse WHOIS association
- Traffic rank analysis
- Company registration check
AI Deep Investigation
Cross-check the story, claims, and supporting evidence before you decide
- Everything in Advanced Scan
- AI website content analysis
- AI cross-reference verification
- Claim authenticity validation
- Detailed report with evidence
Comprehensive Investigation
Full-spectrum investigation with company deep search & social intelligence
- Everything in Deep Investigation
- AI company background search
- Social media intelligence
- Detailed suspicious point analysis
- Event timeline & entity connections
This analysis is for informational purposes only and does not constitute a legal determination.
Security Sources
Domain Information
- DNSSEC
- Disabled
SSL/TLS Certificate
No data available
Server Information
- IP Address
- 31.59.121.53
- Hosting Provider
- CGI GLOBAL LIMITED
- ASN
- AS56971 AS56971 Cloud
- Server Location
- Paris, France
- Organization
- Cloudbackbone
Related Intelligence
Technical Details (DNS / Headers / Subdomains)
DNS Records
Email Security
SPF Not Configured DMARC Not Configured| Type | Value |
|---|---|
| A | 31.59.121.53 |
HTTP Security Headers
0/6Channels / Subdomains
No data available
Community Reports
Log in to report and share your experience
Proceed with Caution
There is no strongest risk signal yet, but the domain alone is not enough to clear the case
If the case still involves shopping, investment, recovery, or branded support claims, a scenario-based review is usually more valuable than just refreshing the result.
Recommended First
Open the matching scenario guide
Continue by the actual scenario such as an investment platform, online store, or recovery service.
Verify the company or brand identity
Confirm whether the business or brand behind the domain is real.
Review the chat or direct-message script
Many otherwise normal-looking sites become risky because of the pitch, pressure, and payment instructions behind them.
If already affected, move into the action plan
If money or account data were already exposed, do not stay in the normal verification flow.
The results are based on multiple third-party data sources and AI models. False positives or negatives may occur. This report should not be used as the sole basis for any decision. Please verify with additional sources.
Continue with the actual scenario check
If this is a store, investment platform, or recovery service, do not rely on the domain alone. Continue with the matching scenario guide.
If you already paid, logged in, or downloaded files, move into the action plan immediately.
Related Security Guides
Learn more about how to protect yourself from this type of threat.
Understanding this threat
FAQ
Is 97ee5.catex.at safe to visit?
97ee5.catex.at received a trust score of 88/100 from ScamLens, based on analysis of 30+ threat intelligence sources. No significant threats were detected. The site appears safe and trustworthy.
Was 97ee5.catex.at flagged by any threat databases?
97ee5.catex.at was flagged by 2 out of 30+ threat intelligence sources. Specifically flagged by: openphish, phishing_army. The detected threat categories include: general threat.
How old is 97ee5.catex.at?
Registration date information for 97ee5.catex.at is not publicly available through WHOIS records, which can itself be a risk indicator.
Does 97ee5.catex.at use HTTPS and have a valid SSL certificate?
ScamLens could not verify the SSL certificate details for 97ee5.catex.at during this scan. Treat this as unavailable evidence, not as proof that the site is safe or unsafe.
What security headers does 97ee5.catex.at implement?
97ee5.catex.at is missing important security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security, Referrer-Policy, Permissions-Policy. Missing security headers can leave visitors vulnerable to cross-site scripting (XSS) and other web-based attacks.
What does the ScamLens community think about 97ee5.catex.at?
No community votes or reports have been submitted for 97ee5.catex.at yet. You can be the first to share your experience.
Where is 97ee5.catex.at hosted?
97ee5.catex.at is hosted by CGI GLOBAL LIMITED in Paris, France (ASN: ASAS56971 AS56971 Cloud).
What should I do about 97ee5.catex.at?
Do not visit or interact with this domain. Do not enter any credentials. [INFERENCE] If you intended to access X (formerly Twitter), navigate directly to x.com or use official X mobile apps instead of clicking external links. Report this domain to X's trust and safety team and to phishing databases. Consider blocking it at your network or device level.
Is this report useful?
Use this report to remind others to verify the shopping, investment, or support scenario instead of treating it as full clearance.
Forward to your parents — they deserve to browse safely too.
About this analysis
This report is generated from real-time data across 90+ threat intelligence sources, combined with AI analysis and community feedback.
Learn about our scoring methodology | Last analyzed: June 23, 2026