Security Scan Report: clickfraud.ru

Site favicon
Submitted: Sep 26, 2026, 3:21:59 PMCompleted: Sep 26, 2026, 3:23:04 PMpubliccompleted

This website contacted 22 IPs in 3 countries across 17 domains to perform 148 HTTP transactions. The main domain is clickfraud.ru and was registered 21 years ago.

Submitted URL: https://clickfraud.ru

The Cisco Umbrella rank of the primary domain is #556,329 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 70%

2
Risk Score

Established click-fraud protection service with no credential/payment forms or concrete threat hits. Weak JS/redirect signals and a low-confidence phishing label warrant only low risk.

Risk Factors (4)
Presence of an eval() call (dynamic code execution)
Right-click context menu disabled
Seven cross-domain redirects detected
ML classifier returned a 48% phishing scam label
Safety Factors (5)
Domain is over 6 years old and well-established
No credential, login, or payment forms on the page
No Indicators of Compromise, YARA, IDS, or Safe Browsing matches
Self-branded service (CLICKFRAUD) matching its own domain
Normal third-party resources (analytics, chat, fonts)
Domain age information unavailable

Details

Page Title

Защита от скликивания контекстной рекламы Яндекс и Гугл

Scan Type

public

Domain Name Analysis

The domain name 'clickfraud.ru' uses the Russian country-code top-level domain (.ru) with no subdomain. The core label 'clickfraud' covers 10 characters split between 3 vowels and 7 consonants. Splitting it apart reveals two words: click, fraud. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://clickfraud.ru

Page Load Overview

9.10s
Total Load Time
3.4 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru-RU
Text Length:17,348 chars
Detector Agreement:80%

Website Classification

Primary Category

phishing scam48% confidence
Type: spa
Method: ml+structural

All Detected Categories

phishing scam
48%
technology software
44%
corporate business
37%
government public service
36%
corporate
35%

Detected Features

Comments
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2278.24.180.143St Petersburg, St.-Petersburg, Russia
AS49505JSC Selectel
6104.21.27.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.250.154.95Google · CDNUnited States
AS15169Google LLC
6142.251.14.97Google · CDNUnited States
AS15169Google LLC
6142.251.110.94Google · CDNUnited States
AS15169Google LLC
6172.67.142.245Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
677.88.21.119Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
6104.26.14.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
662.76.26.238Moscow, Moscow, Russia
AS61400Start2 LLC
690.156.233.120Russia
AS47764LLC VK
14822--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10C8429D13A676138700FB3DF8013792C34916CEEEA2596C5E6B01956F2F1C983FE5A86

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:GxPPTH75LtGZbnDpkf/KexbJJ/3ctv0axvhcwsE4DZlsVMUhI:FDpkf/K4N3ctv0axvhcwsE4DZloI

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:377719:GHA2BiIjJQjIQxgtEwXGFMALoGBQlBMQmIBkLnkAcWQkgAgCKknKYEVwRAUIpCKYAQZgQCMMtXDwbAQURgoQlAMAWAgKzCmJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:02046e2c64200064
Perceptual Hash:92936c6d96929667
Difference Hash:d4c9c9c9c9c7c1cd
Wavelet Hash:420d7f2d6571017f
Color Hash:#56ac53

Scan History

Scan history not available

Unable to load historical scan data