Security Scan Report: ckrotbin.biz

Site favicon
Submitted: Sep 26, 2026, 2:29:10 PMCompleted: Sep 26, 2026, 2:29:44 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Forged Income Tax Department penalty notice on a 3-day-old .biz domain, using legal threats and a fake document download to impersonate the Government of India. Do not download files or respond.

Risk Factors (5)
Impersonation of a different entity's brand (Indian Income Tax Department / Government of India) on a non-official domain
Newly registered domain (3 days old) with no reputation ranking in Cisco Umbrella
Fabricated official memorandum with forged officer signature and fake '[email protected]' contact
Coercive deadline and legal-threat language designed to panic the recipient
Unsolicited document-download call to action on a .biz domain, a common malware-delivery lure
Domain age information unavailable

Details

Page Title

कर दंड सूचना - भारत सरकार

Scan Type

public

Domain Name Analysis

The domain 'ckrotbin.biz' uses the business-focused generic top-level domain (.biz). The second-level label 'ckrotbin' is 8 characters long containing 2 vowels alongside six consonants. It segments into 3 words: ck, rot, bin. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ckrotbin.biz/

Page Load Overview

1.28s
Total Load Time
42 KB
Total Size

Language Analysis

Primary Language

🇮🇳Hindi
Code: hi
Confidence:80%
Script:Devanagari
Direction:ltr

Detection Details

HTML Lang Attribute:hi
Text Length:1,463 chars
Detector Agreement:50%

Website Classification

Primary Category

government public service100% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
100%
social media network
99%
download file sharing
99%
technology software
99%
blog personal website
99%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.21.71.168Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.147.112Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
52--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11072645EE7B331216417B46837AB5B3336B49023D60BC9653E9CA388DF85DE049A335C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:6cwusNVU+hQhCv8s2VqXlXTQiD8VyJmLOcmMy6rjTunwrPDBf2XnPrMIircQ9:MO+6syLO2unwbDgn1iYs

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17034:iUSAhINEKTSIgIxawAVAYiXAQiI3ASsAAkWtBZ8TQsQIYkDIRSpGOAUYAASBwEBANQFgKQsijRGgAAwBiENiEAM5t8ALgMQC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c4eebcbce6f6a5e7
Perceptual Hash:f3d933319926cc26
Difference Hash:5848686808284d49
Wavelet Hash:262e3c3c0404063f
Color Hash:#52862d

Other Hashes

Crop Resistant:5848686808284d49

Scan History

Scan history not available

Unable to load historical scan data