Security Scan Report: knigka.info

Site favicon
Submitted: Oct 2, 2026, 8:20:01 AMCompleted: Oct 2, 2026, 8:20:41 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 72%

2
Risk Score

Established Russian e-book library (3.6-yr-old domain) with its own same-origin login form; no Indicators of Compromise, malware, or impersonation. The 'CHASE branding' phishing flag is a false positive.

Risk Factors (3)
Domain is unranked in Cisco Umbrella top 1M (weak prior only)
5 cross-domain redirects detected
Unranked third-party script host elpushnot.com along with Russian ad/analytics networks (ad.mail.ru, gnezdo.ru)
Safety Factors (4)
Domain age 1307 days, categorized WELL_ESTABLISHED with minimal risk level
Own-brand login form on its own registered domain — not brand impersonation
No credential exfiltration, no cross-origin credential forms
No threat-intelligence, YARA, IDS, or Safe Browsing detections
Domain age information unavailable

Details

Page Title

Скачать электронные книги: Упрощенная система налогобложения, учета и отчетности, Уход за больными после инсульта. Учебное пособие по реабилитации, Технологические мет...

Scan Type

public

Domain Name Analysis

The domain name 'knigka.info' uses the informational generic top-level domain (.info) with no subdomain. Count 6 characters in 'knigka' with two vowels and four consonants. Splitting it apart reveals three words: k, nig, ka. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://knigka.info

Page Load Overview

3.18s
Total Load Time
789 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:70%
Script:Cyrillic
Direction:ltr

Detection Details

Text Length:12,525 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical64% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
64%
government public service
64%
entertainment media
57%
real estate property
53%
corporate business
49%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1795.215.205.165Dronten, Flevoland, Netherlands
AS204601NovoServe B.V.
377.88.44.55Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
3136.243.73.146Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
3185.148.37.79Russia
AS48347JSC Mediasoft ekspert
35.255.255.77Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
3172.205.28.125Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
394.139.255.28Asbest, Sverdlovsk Oblast, Russia
AS208677Cloud.ru
3155.212.203.195Moscow, Moscow, Russia
AS47764LLC VK
388.212.201.204Moscow, Moscow, Russia
AS39134Edinaya Set Limited Liability Company
3142.251.13.139Google · CDNUnited States
AS15169Google LLC
8323--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B59322F3108D6C7F1304E69BE8207F5DACAF5AFF7FC7990750B6086A79C2660851894A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:sn2GsiE2+Mq6jYwwM6d9tYCSm8qdEN4M0Gnshp:sn2GsiE2+MqKYwwf9tYrfqdEN4M0vp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:91466:gIAJikmYwpwAmhgqBkpKBBYOsA4jV8tyIzBJajowCOYHRs/CgDEBIBSQDSIiIkKROjQkahlUQQGAM7RBcQAxAhSpVASVBBCM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:8080ff979fffff87
Perceptual Hash:bf57611c3ec1c09c
Difference Hash:504c4b772309715f
Wavelet Hash:8080839f83ffbf83
Color Hash:#d22d7a

Other Hashes

Crop Resistant:504c4b772309715f

Scan History

Scan history not available

Unable to load historical scan data