Security Scan Report: www.bulnews.bg

Redirected to: https://1wirpm.com/?open=register&p=l83c

Submitted: Nov 12, 2025, 6:51:01 PMCompleted: Nov 12, 2025, 6:52:01 PMpubliccompleted
Loading additional data...

Summary

This website contacted 109 IPs in 7 countries across 32 domains to perform 370 HTTP transactions. The main domain is 1wirpm.com and was registered NaN years ago.

Submitted URL: https://www.bulnews.bg/article/296561?s-news-7638678-2025-11-10-peru-se-enfrenta-a-rusia-en-busca-de-su-primera-victoria-bajo-la-direccion-de-barreto-en-amistoso-internacional=

Effective URL: https://1wirpm.com/?open=register&p=l83cRedirected

AI Security Verdict

High Risk

Confidence: 95%

10
Risk Score

Site is malicious due to known bad IP and suspicious new domain redirects.

Risk Factors
Presence of malicious Indicators of Compromise (suspicious IP)
Very new domain age (<90 days) with low reputation
Unranked domain in Cisco Umbrella (poor reputation)
Redirect to a different, unrelated domain
Domain age information unavailable

Details

Page Title

1w: Online Casino & Sport Betting - 2030807.5672038472

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

adult content

(63%)

Domain Information

Within the Bulgarian country-code top-level domain (.bg), 'www.bulnews.bg' is registered; it also runs on subdomain 'www'. The second-level label 'bulnews' is 7 characters long containing two vowels alongside 5 consonants. Breaking it apart gives two words: bul, news. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.bulnews.bg/article/296561?s-news-7638678-2025-11-10-peru-se-enfrenta-a-rusia-en-busca-de-su-primera-victoria-bajo-la-direccion-de-barreto-en-amistoso-internacional=

Page Load Overview

13.12s
Total Load Time
370
HTTP Requests
32
Domains
2.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-001
Text Length:1,644 chars
Detector Agreement:75%

Website Classification

Primary Category

adult content63% confidence
Type: static
Method: ml+structural

All Detected Categories

adult content
63%
gambling betting
41%
cryptocurrency blockchain
34%
corporate business
27%
news
15%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
46142.250.185.195United States
AS15169GOOGLE
3142.250.181.230United States
AS15169GOOGLE
3194.67.193.129Russia
3142.250.186.131United States
AS15169GOOGLE
354.39.128.162Beauharnois, Quebec, Canada
AS16276OVH SAS
3142.250.185.134United States
AS15169GOOGLE
3188.114.97.3United States
AS13335CLOUDFLARENET
3142.250.184.227United States
AS15169GOOGLE
3142.250.185.194United States
AS15169GOOGLE
3157.240.0.6Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
370109--

Content Similarity HashesFor malware variant detection

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data