Security Scan Report: rolvera.vip

Redirected to: https://rolvera.vip/main.php?region=europe

Submitted: Apr 3, 2026, 6:52:05 PMCompleted: Apr 3, 2026, 6:53:13 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 1 country across 4 domains to perform 15 HTTP transactions. The main domain is rolvera.vip and was registered NaN years ago.

Submitted URL: http://rolvera.vip/main.php?region=europe

Effective URL: https://rolvera.vip/main.php?region=europeRedirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Site impersonates Revolut on a newly registered, unranked domain with an email form – high‑risk phishing.

Risk Factors
Brand impersonation (Revolut) on a brand‑new, unranked domain
Domain age less than 7 days (critical risk)
Email collection form used in a brand‑impersonation context
Domain age information unavailable

Details

Page Title

Revolut

Scan Type

public

Language

🇷🇺

Russian

(80% confidence)

Category

technology software

(60%)

Domain Information

You're looking at domain 'rolvera.vip' on the .vip top-level domain with no subdomain. The second-level label 'rolvera' is 7 characters long holding 3 vowels versus four consonants. Tokenizing the label suggests 2 words: r, olvera. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://rolvera.vip/main.php?region=europe

Page Load Overview

0.49s
Total Load Time
15
HTTP Requests
4
Domains
172 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

Language Code:ru
Detection Confidence:80%
Script Type:Cyrillic
HTML Lang Attribute:ru
Text Length:6,219 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software60% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
60%
finance banking
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5188.114.97.3United States
AS13335Cloudflare, Inc.
2151.101.130.137United States
AS54113Fastly, Inc.
2104.16.174.226United States
AS13335Cloudflare, Inc.
2188.114.96.3United States
AS13335Cloudflare, Inc.
2104.16.175.226United States
AS13335Cloudflare, Inc.
2104.26.9.44United States
AS13335Cloudflare, Inc.
156--

Detected Technologies3

JQueryv3.7.0
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115D3AB33026934270137C2D520A95B37E6969D5FFAA70A043EECDBF72FEAC90745A119

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:3JtBKpZRTknPS9I2IEBa4QuoWKJ39ywBxXvXdRoM:3JtBKlKJ6KJ39ywBxXvXdRJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137359:aB2JBcA1TAJgiUBBECBiQABgDEAoQ6KFnkWuwFkAaw1oMUQii4SAAQ0ATlvWASAcgVnAMOhGAcCBMAsAaZoUgAKBDihARKAD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f7e78f8f0c0c0c0
Perceptual Hash:cc8732b2cf6d306c
Difference Hash:fcf8f272668d9287
Wavelet Hash:7f7e78f8f0c0c0c0
Color Hash:#78493a

Scan History

Scan history not available

Unable to load historical scan data