Security Scan Report: cdn.master-knives.ru

Site favicon
Submitted: Sep 24, 2026, 2:02:36 PMCompleted: Sep 24, 2026, 2:03:10 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

6
Risk Score

Encoded JS interstitial on an old domain that chains 6 cross-domain redirects and POSTs to a threat-flagged kill-bot.ru host. No forms or malware, but behaviour warrants caution.

Risk Factors (4)
Six chained cross-domain redirects obscuring the destination
Cross-origin POST to a domain reported as a known attacker
Encoded/obfuscated inline JavaScript with a network sink
Interstitial 'verification' page unrelated to the 28-year-old merchant domain it is delivered from
Safety Factors (4)
Domain master-knives.ru is ~28 years old (registered 1998), well-established
No credential, password, or payment forms detected (0 forms total)
No YARA malware patterns and no high-precision native-YARA hits
No Google Safe Browsing or phishing/malware IDS alerts (only an INFO heuristic)
Domain age information unavailable

Details

Page Title

User verification...

Scan Type

public

Domain Name Analysis

The domain name 'cdn.master-knives.ru' uses the Russian country-code top-level domain (.ru) and includes subdomain 'cdn'. The registrable portion 'master-knives' spans 13 characters split between four vowels and eight consonants; it also includes one hyphen. Word splitting yields two words: master, knives. The median word length lands at six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cdn.master-knives.ru

Page Load Overview

0.35s
Total Load Time
198 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Text Length:295 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software65% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
65%
e-commerce shopping
50%
documentation technical
50%
news media journalism
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7178.176.128.203Russia
AS31133PJSC MegaFon
231.192.105.204Moscow, Moscow, Russia
AS50867Hostkey B.v.
246.29.114.75Russia
AS48347JSC Mediasoft ekspert
2212.41.11.153Moscow, Moscow, Russia
AS50340JSC Selectel
2212.108.82.180Netherlands
AS57043Hostkey B.v.
2147.93.136.189St Louis, Missouri, United States
AS40021Contabo Inc.
2194.233.71.78Singapore, Singapore
AS141995Contabo Asia Private Limited
287.250.251.119Yandex · CLOUDRussia
AS13238YANDEX LLC
2190.115.31.218United Arab Emirates
AS59692IQWeb FZ-LLC
287.250.250.119Yandex · CLOUDRussia
AS13238YANDEX LLC
2711--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12CA3B89D85B3243604377079EBBF754D36A180039505DB33BC5C8AA6EFD0A354AF6BA8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:BCDNG/oNHBluT7fSr6t8h9MME2SvJOzW7oC1:B6NG/e0T7fSrdC1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:102162:kQPXBElgowoSkGpAnACEIdqGCUIFIBMkF3ujSGLSkoAiCAAMqAkHeNGGBZCDWGwwqGhAbYEBOSuHrECSAAaBhCTUghnBAEGm

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffe7
Perceptual Hash:b38ccc3333cccc33
Difference Hash:0000000808080008
Wavelet Hash:30303c24273f3f27
Color Hash:#bf9540

Other Hashes

Crop Resistant:0000000808080008

Scan History

Scan history not available

Unable to load historical scan data