Security Scan Report: ct484363-wordpress-dt6v9.tw1.ru

Redirected to: https://vh456.timeweb.ru/blocked/?ref=ct484363-wordpress-dt6v9.tw1.ru#59cf1ca22830817d7

Site favicon
Submitted: Nov 23, 2025, 12:37:44 AMCompleted: Nov 23, 2025, 12:38:33 AMpubliccompleted
Loading additional data...

Summary

This website contacted 20 IPs in 3 countries across 11 domains to perform 57 HTTP transactions. The main domain is vh456.timeweb.ru.

Submitted URL: https://ct484363-wordpress-dt6v9.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#59cf1ca22830817d7

Effective URL: https://vh456.timeweb.ru/blocked/?ref=ct484363-wordpress-dt6v9.tw1.ru#59cf1ca22830817d7Redirected

The Cisco Umbrella rank of the primary domain is #163,229 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 75%

3
Risk Score

Site shows signs of a compromised WordPress installation but lacks phishing forms; low risk overall.

Risk Factors
Compromised WordPress site indicator (internal WP directories present)
Low ranking domain (rank > 100k)
Domain age unknown / potentially newly registered
Safety Factors
No password, email, or payment fields detected
No malicious Indicators of Compromise matches found
Final URL displays a generic block page rather than a phishing landing page
Domain age information unavailable

Details

Page Title

Домен заблокирован в Timeweb

Scan Type

public

Language

🇷🇺

Russian

(60% confidence)

Category

corporate business

(41%)

Domain Information

You're looking at domain 'ct484363-wordpress-dt6v9.tw1.ru' on the Russian country-code top-level domain (.ru); it also runs on subdomain 'ct484363-wordpress-dt6v9'. The core label 'tw1' covers 3 characters holding zero vowels versus 2 consonants; bonus characters include one digit. Tokenizing the label suggests 2 words: tw, 1. Median word length is 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ct484363-wordpress-dt6v9.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#59cf1ca22830817d7

Page Load Overview

1.04s
Total Load Time
57
HTTP Requests
11
Domains
1.3 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:60%
Script:Cyrillic
Direction:ltr

Detection Details

Language Code:ru
Detection Confidence:60%
Script Type:Cyrillic
HTML Lang Attribute:en
Text Length:1,736 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ru

Website Classification

Primary Category

corporate business41% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
41%
technology software
39%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1492.53.96.141Russia
AS9123Jsc timeweb
837.9.64.225Russia
AS13238YANDEX LLC
887.250.251.119Russia
AS13238YANDEX LLC
8142.250.184.195United States
AS15169GOOGLE
677.88.44.55Russia
AS13238YANDEX LLC
387.250.250.119Russia
AS13238YANDEX LLC
277.88.21.119Russia
AS13238YANDEX LLC
277.88.55.88Russia
AS13238YANDEX LLC
25.255.255.77Russia
AS13238YANDEX LLC
22a00:1450:4001:812::2004Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
5720--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D363C7E701F0D0E14A4FC3B19D365A9B9D7624BFDE81928479DC0A507F92DF58883AAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:kHfGeFKP7VuQdqCHG0PxiHm/ouVHHMjEENRzigLIN0:kHf5GBuQdqCHG0AupMVbLIG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:72932:EKQBCRG0BTBsBEASMRQBAhgSohMJFGZAIISIqmTAUEBsdJhwcExJeDEgQogKCaoKgCBQGMZzIgBMAQYiai9E+CkADgggCgQQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:818181ffffffffff
Perceptual Hash:ba3b3ac0c5c5c5c5
Difference Hash:2b2b0b36f0c0b8e8
Wavelet Hash:808080807f7f7f7f
Color Hash:#9ad279

Scan History

Scan history not available

Unable to load historical scan data