Security Scan Report: rtpmegagacor.icu

Redirected to: https://rtpmegagacor.icu/wp-login.php?redirect_to=https%3A%2F%2Frtpmegagacor.icu%2Fwp-admin%2F&reauth=1

Submitted: Nov 26, 2025, 3:47:47 PMCompleted: Nov 26, 2025, 3:50:51 PMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 2 countries across 4 domains to perform 31 HTTP transactions. The main domain is rtpmegagacor.icu and was registered NaN years ago.

Submitted URL: https://rtpmegagacor.icu/wp-admin/

Effective URL: https://rtpmegagacor.icu/wp-login.php?redirect_to=https%3A%2F%2Frtpmegagacor.icu%2Fwp-admin%2F&reauth=1Redirected

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

High‑risk phishing site likely using a hacked WordPress installation

Risk Factors
Compromised WordPress URL paths
Brand‑new domain (<7 days old)
Unranked/low‑reputation domain
Domain age information unavailable

Details

Page Title

Bot Verification

Scan Type

public

Language

🇺🇸

English

(65% confidence)

Category

unknown

(0%)

Domain Information

Within the .icu top-level domain, 'rtpmegagacor.icu' is registered without a subdomain. Its registrable label 'rtpmegagacor' stretches across 12 characters with 4 vowels and 8 consonants. Word splitting yields 4 words: rtp, mega, gac, or. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rtpmegagacor.icu/wp-admin/

Page Load Overview

1.65s
Total Load Time
31
HTTP Requests
4
Domains
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:65%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:65%
Script Type:Latin
Text Length:54 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13216.58.212.131United States
AS15169GOOGLE
9142.250.186.99United States
AS15169GOOGLE
5142.250.184.227United States
AS15169GOOGLE
4188.114.97.3United States
AS13335CLOUDFLARENET
3188.114.96.3United States
AS13335CLOUDFLARENET
32a00:1450:4001:830::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
32a06:98c1:3120::3United States
AS13335CLOUDFLARENET
32a06:98c1:3121::3United States
AS13335CLOUDFLARENET
32a00:1450:4001:831::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
32a00:1450:4001:828::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
3110--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T122A19675097210149C2383E1A6F2778965629313F6869AA078FD5724EF8DDF2C493BA8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:LrlklWJ6wUmpK7AxGJIi+K5EgpJOynZex08/:KlWJ6wUmpK7kGJIKagu/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4935:gIEEFgUgAaEwgAFAgAAAQhEoWgSACoOAEQBRGDAwAAkJwkAAVimAQSggCCEBBgAKANABwBAQRAADSSwKQAZCcAADiAABAIQi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3c3c3c3c3c3f7
Perceptual Hash:e432ce31cc338b9b
Difference Hash:9696969696969606
Wavelet Hash:c3c3c3c3c3c3c3e2
Color Hash:#2d8633

Scan History

Scan history not available

Unable to load historical scan data