Security Scan Report: r3.galerix.ru

Site favicon
Submitted: Oct 5, 2026, 6:01:22 AMCompleted: Oct 5, 2026, 6:02:42 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 72%

2
Risk Score

Self-branded Gallerix art-museum subdomain with no credential or payment forms, no threat-intel, YARA or IDS hits. Only routine Yandex analytics and a tracking script. Low risk.

Safety Factors (5)
Self-branded page whose title matches its own domain family (galerix.ru / r3.galerix.ru)
No credential or payment collection: all form-field counts are zero for password, disguised-password and payment inputs
Forms post to the site's own domain (//gallerix.ru/roster/, /user/join/) — no cross-origin form action or credential exfiltration
No Indicators of Compromise, no YARA malware hits, no IDS alerts, no obfuscated or exfiltrating JavaScript
Established-looking, content-heavy art portal with substantial original text and internal navigation
Domain age information unavailable

Details

Page Title

Живопись, картины и художники – онлайн-музей Gallerix

Scan Type

public

Domain Name Analysis

Domain 'r3.galerix.ru' uses the Russian country-code top-level domain (.ru), featuring subdomain 'r3'. The registrable portion 'galerix' spans 7 characters with 3 vowels and 4 consonants. Tokenizing the label suggests 3 words: gale, r, ix. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://r3.galerix.ru

Page Load Overview

77.44s
Total Load Time
N/A
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru
Text Length:31,412 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning59% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
59%
phishing/scam
20%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16185.229.9.163Russia
AS3175Citytelecom LLC
1392.53.105.158St Petersburg, St.-Petersburg, Russia
AS9123Jsc timeweb
13195.209.216.63Russia
AS35598Inetcom Carrier LLC
1362.173.140.180Russia
AS34300Internet-Cosmos LLC
13194.87.218.241Novosibirsk, Novosibirsk Oblast, Russia
AS207713Global Internet Solutions LLC
13104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1377.88.21.119Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
1387.250.251.119Yandex · CLOUDRussia
AS13238YANDEX LLC
08--

Detected Technologies2

JQueryv3.5.1
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D8E3B9718185647F0312B18BEA18BF0D79EB41FE9F67471113F42DEA3AF2C94CA29619

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:KcYGnFY3zAMVavaYdCzBTLgOIQjLfO0nzFEb4/oTRZNHLjwBVw6PRf3:FYGnFY3cMViaYdCBuQXfO0zFKJLjGK6R

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:156589:xZLYIxUECCQIAGkBg4DIyAApUSiAXBzCCgIgAmUH9gozQDYUauQxUEgFBC4AHTiICxeQaAyBQwclmVsqBBAIQArSAwYFMJHB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00007f7f3f7f7f20
Perceptual Hash:827e7c3f7b80a581
Difference Hash:28b0cbebebebd1c9
Wavelet Hash:00007f3f2f7f7f00
Color Hash:#405bbf

Scan History

Scan history not available

Unable to load historical scan data