Security Scan Report: my-farmer.ru

Site favicon
Submitted: Sep 25, 2026, 4:44:35 PMCompleted: Sep 25, 2026, 4:45:32 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Established-looking Russian farming blog showing signs of compromise: loads a malware-flagged third-party resource, triggers a CRITICAL phishing IDS alert, uses eval/Function, and beacons off-origin to ip.mehanoid.pro.

Risk Factors
Loads a script from a domain flagged as WordPress-injection malware
CRITICAL IDS phishing / OAuth redirect alert on the session
Dynamic code execution (eval / Function constructor) on a content blog
Cross-origin POST to an unrelated domain (ip.mehanoid.pro)
Injected affiliate/redirect links and mismatched Open Graph metadata typical of a compromised/spam site
Domain age information unavailable

Details

Page Title

Справочник фермера

Scan Type

public

Domain Name Analysis

You're looking at domain 'my-farmer.ru' on the Russian country-code top-level domain (.ru) and has no subdomain. The registrable portion 'my-farmer' spans 9 characters split between 2 vowels and six consonants; it also includes one hyphen. Segmentation suggests two words: my, farmer. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://my-farmer.ru

Page Load Overview

17.07s
Total Load Time
4.2 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru-RU
Text Length:3,136 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical99% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
99%
real estate property
92%
finance banking
76%
adult content
29%
corporate
25%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
545.12.19.245St Petersburg, St.-Petersburg, Russia
AS198610Beget LLC
3142.251.14.95Google · CDNUnited States
AS15169Google LLC
3142.132.202.70Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
3185.148.37.79Russia
AS48347JSC Mediasoft ekspert
345.43.142.8United Kingdom
AS16276OVH SAS
346.4.218.122Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
387.250.250.119Yandex · CLOUDRussia
AS13238YANDEX LLC
3104.21.56.218Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
377.88.21.119Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
29397--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15DF32AB150A930BB31A363E8A140770C7773E617C9034A4572BC99F8BFA2D9A887775D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:V6GmYJY1MeTGy8qYkgScwdgYxZ2gqghgbQxH6O5Gf+kbRe:V6AJOTJySEI4gqghgbQxa4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:161231:CQCIQhFEmdAoV6ojkoE1KaKAQpYplSwAiFAgAoBMhCAB3YQCCp2IEosATIgWKWIIVGQEihUNCVMGloBJyDIBAQ5UxwQXY1NQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000fb73f371ffff
Perceptual Hash:ed181a6d1b006cff
Difference Hash:b1d196c643c38700
Wavelet Hash:00007331f131ffff
Color Hash:#53ac93

Scan History

Scan history not available

Unable to load historical scan data