Security Scan Report: gov-xnui.com

Site favicon
Submitted: Sep 17, 2026, 9:47:41 AMCompleted: Sep 17, 2026, 9:48:02 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Fake Income Tax Department penalty notice on a 58-day-old, unranked domain flagged as content malware (venomrat RAT). Impersonates the Government of India to push a malicious download — do not open or download anything.

Risk Factors
Government brand impersonation on a non-government, unranked domain (58 days old)
Content-malware threat-intel match on the primary domain (venomrat/papermill, multi-feed)
Obfuscated JavaScript (eval + encoding functions)
Coercive legal-threat and 72-hour deadline language
Offers a 'Download Documents' payload rather than functioning as a real government portal
Domain age information unavailable

Details

Page Title

कर दंड सूचना - भारत सरकार

Scan Type

public

Domain Name Analysis

The domain name 'gov-xnui.com' uses the commercial generic top-level domain (.com) with no subdomain. The core label 'gov-xnui' covers 8 characters split between three vowels and 4 consonants, notching one hyphen. Tokenizing the label suggests three words: gov, x, nui. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gov-xnui.com

Page Load Overview

1.40s
Total Load Time
68 KB
Total Size

Language Analysis

Primary Language

🇮🇳Hindi
Code: hi
Confidence:80%
Script:Devanagari
Direction:ltr

Detection Details

HTML Lang Attribute:hi
Text Length:1,463 chars
Detector Agreement:50%

Website Classification

Primary Category

government public service100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
100%
social media network
99%
download file sharing
99%
real estate property
99%
blog personal website
99%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2172.67.178.250Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2106.74.32.242China
AS133118China Unicom IP network
2117.187.133.33China
AS138407The Internet Data Center of Guizhou Mobile Communication Company Limited
2104.21.59.139Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
84--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T195C02BFFBC341C490C947FA47CE6631ACC2D86AC7461EF01B9D251F23AA07948D24384

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3:PouVWJhquHbsYXM6BYqNagGHOHz8j2PQZuHFLZqgYqA3oxCHb0WGXI9kBbZWM:h4hqIYYXBuqNrQOHzg2ZIvqCoxCJuB9d

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:37d461cc444033ba60f627f63789ab3c

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c4eebcbce6f6a5e5
Perceptual Hash:f3d933319926cc26
Difference Hash:5848686808284d49
Wavelet Hash:262e3e3e0606063f
Color Hash:#3a4978

Other Hashes

Crop Resistant:5848686808284d49

Scan History

Scan history not available

Unable to load historical scan data