Security Scan Report: nrmsoft.ru

Site favicon
Submitted: Dec 26, 2025, 4:42:34 AMCompleted: Dec 26, 2025, 4:43:10 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 9 domains to perform 101 HTTP transactions. The main domain is nrmsoft.ru.

Submitted URL: https://nrmsoft.ru

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Site hosts a login form on an unranked, likely new domain with many redirects – high risk of phishing.

Risk Factors
Credential harvesting form on low-reputation domain
Excessive redirects (6)
Potentially newly registered domain
Domain age information unavailable

Details

Page Title

Норма СОФТ

Scan Type

public

Language

🇷🇺

Russian

(60% confidence)

Category

technology software

(74%)

Domain Information

You're looking at domain 'nrmsoft.ru' on the Russian country-code top-level domain (.ru) with no subdomain. The core label 'nrmsoft' covers 7 characters split between 1 vowel and 6 consonants. It segments into three words: nr, m, soft. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nrmsoft.ru

Page Load Overview

15.27s
Total Load Time
105
HTTP Requests
10
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:60%
Script:Cyrillic
Direction:ltr

Detection Details

Language Code:ru
Detection Confidence:60%
Script Type:Cyrillic
Text Length:2,647 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software74% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
74%
documentation technical
63%
social_media
25%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1577.88.21.119Russia
AS13238YANDEX LLC
15185.71.66.141Russia
AS43298Storm Networks LLC
15142.250.185.234Russia
15178.208.94.212Moscow, Moscow, Russia
AS210079EuroByte LLC
15104.16.175.226United States
AS13335CLOUDFLARENET
15217.16.19.172Russia
AS47764LLC VK
15142.250.185.195RussiaUnknown
1057--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AD13C62195BD4CAB011151C1F8306F4EB8DB957BDB078852B2FE0AB6BFC7D948E1B189

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:3X6wXg6JhdE6GfPQdgsQuto12yFQp8NkGqy8UQacWbxoMUbokLIh3QjW8s5y:37XjJhdE6GfPQdgDzQyuGqy8UQacWnpG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:42192:lwogYoRQAAAo4QDEgRxQAG6pULybUeSQBF0HwKFSIoJFioNkKERDCTI+AKPQFOgkBISGAXQCWa4ZIBQoIQAAecYBiUc6pQDM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fbc3c3c3c3ffffff
Perceptual Hash:fc3dc3874b255231
Difference Hash:7216161616290611
Wavelet Hash:00c38383c3dff7e8
Color Hash:#87c5b2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data