Security Scan Report: co515685-wordpress-ixd7o.tw1.ru

Redirected to: https://vh454.timeweb.ru/blocked/?ref=co515685-wordpress-ixd7o.tw1.ru

Submitted: Oct 16, 2025, 3:00:00 AMCompleted: Oct 16, 2025, 3:03:59 AMpubliccompleted
Loading additional data...

Summary

This website contacted 20 IPs in 3 countries across 10 domains to perform 43 HTTP transactions. The main domain is vh454.timeweb.ru.

Submitted URL: https://co515685-wordpress-ixd7o.tw1.ru/wp-content/plugins/nwca-ddcanw/nwca-ddcanw/pages/region.php?lca#83679692d3670a509

Effective URL: https://vh454.timeweb.ru/blocked/?ref=co515685-wordpress-ixd7o.tw1.ruRedirected

AI Security Verdict

High Risk

Confidence: 90%

10
Risk Score

High‑risk phishing site using URL manipulation and compromised WordPress components.

Risk Factors
URL manipulation (high‑risk phishing technique)
Compromised WordPress site paths
Unranked / low‑reputation domain
Unknown / very new domain age
Domain age information unavailable

Details

Page Title

Домен припаркован в Timeweb

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

Within the Russian country-code top-level domain (.ru), 'co515685-wordpress-ixd7o.tw1.ru' is registered with subdomain 'co515685-wordpress-ixd7o'. The second-level label 'tw1' is 3 characters long split between zero vowels and two consonants, notching 1 digit. Breaking it apart gives 2 words: tw, 1. Average segment length settles at 1.5 characters. 'tw' is most common in Albanian usage. Net impression: Albanian phrase with character flair.

Screenshot

Security scan screenshot of https://co515685-wordpress-ixd7o.tw1.ru/wp-content/plugins/nwca-ddcanw/nwca-ddcanw/pages/region.php?lca#83679692d3670a509

Page Load Overview

0.90s
Total Load Time
43
HTTP Requests
10
Domains
885 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,802 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1392.53.96.105Russia
AS9123Jsc timeweb
8216.58.206.67United States
AS15169GOOGLE
737.9.64.225Russia
AS13238YANDEX LLC
777.88.21.119Russia
AS13238YANDEX LLC
287.250.250.119Russia
AS13238YANDEX LLC
25.255.255.77Russia
AS13238YANDEX LLC
277.88.44.55Russia
AS13238YANDEX LLC
287.250.251.119Russia
AS13238YANDEX LLC
22a00:1450:4001:813::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a02:6b8:a::aRussia
AS13238YANDEX LLC
4320--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11073B5E741F0D0E14A4FC3B19D36569BDD7624BFDE85528479DC0A106F82EF98883AAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:jyfFVtrVRcBLoHj0PxiHm/ouVHzMd/ENRzGXLIN0:E3RcBLoHj0Au1MMMLIG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:77922:sMjIymsQKhByoCIQRiAJ4h3Eb4EGOQmFCABIEmUkEqAbIAZIQrIcwSgIE4hECBfHCXAA7GAI00CTlMSEIFQwzQBEIgBIUswT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data