Security Scan Report: ce343112-wordpress-b6a6g.tw1.ru

Site favicon
Submitted: Oct 31, 2025, 3:32:07 AMCompleted: Oct 31, 2025, 3:33:28 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 1 domain to perform 27 HTTP transactions. The main domain is ce343112-wordpress-b6a6g.tw1.ru.

Submitted URL: https://ce343112-wordpress-b6a6g.tw1.ru/wp-content/plugins/DSSDS/pages/region.php

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Phishing page impersonating Crédit Agricole on a hacked WordPress site; treat as high‑risk.

Risk Factors
Compromised WordPress site indicator
Brand impersonation of Crédit Agricole on a suspicious domain
Google Safe Browsing social engineering detection
Unranked domain (not in Cisco Umbrella top 1 M)
Likely newly registered domain
Domain age information unavailable

Details

Page Title

Accès CR - Crédit Agricole

Scan Type

public

Language

🇫🇷

French

(80% confidence)

Category

finance banking

(98%)

Domain Information

Within the Russian country-code top-level domain (.ru), 'ce343112-wordpress-b6a6g.tw1.ru' is registered, featuring subdomain 'ce343112-wordpress-b6a6g'. Count 3 characters in 'tw1' with 0 vowels and two consonants, plus 1 digit. Breaking it apart gives two words: tw, 1. Expect 1.5 characters per word on average. 'tw' is most common in Albanian usage.

Screenshot

Security scan screenshot of https://ce343112-wordpress-b6a6g.tw1.ru/wp-content/plugins/DSSDS/pages/region.php

Page Load Overview

46.54s
Total Load Time
27
HTTP Requests
1
Domains
559 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:fr
Text Length:4,295 chars
Detector Agreement:50%

Website Classification

Primary Category

finance banking98% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
98%
real estate property
90%
government public service
82%
blog personal website
68%
technology software
61%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1392.53.96.105Russia
AS9123Jsc timeweb
132a03:6f00:1::5c35:6069St Petersburg, St.-Petersburg, Russia
AS9123Jsc timeweb
272--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E143B5338150183782E311E6F2B04F1FADF68F5BC6459410A6F183EB43E3E66DA975A9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:BkA5XMhXf+vw3JY/oDBCnjr+WwXjSh6b4M8B/zyCG:+A5XQXf+vw3JY/oDBCnjrsuhOCG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:56632:EpCgIAUEKiFqRIkBEQsgAIhEYUYMwBMwAgiNCADaAAIBA0EaICYk4UDSiAyzkPgD5hnAsAIJniUgwUUCABROUMgyAjiSQggQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data