Security Scan Report: lib39.ru

Site favicon
Submitted: May 15, 2026, 12:30:46 PMCompleted: May 15, 2026, 12:35:14 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 72%

3
Risk Score

The site hosts a legitimate library portal but shows a login form on an unranked, age‑unknown domain and heavily obfuscated JavaScript, warranting moderate risk.

Risk Factors (3)
Unranked domain
Unknown domain age
High JavaScript obfuscation
Safety Factors (4)
Content clearly identifies as a regional scientific library
No Indicators of Compromise or YARA malware matches
No credential exfiltration detected
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 3
Domain age information unavailable

Details

Page Title

Калининградская областная научная библиотекаsecondary capture

Scan Type

public

Domain Name Analysis

The domain name 'lib39.ru' uses the Russian country-code top-level domain (.ru) with no subdomain. The registrable portion 'lib39' spans 5 characters with one vowel and 2 consonants; bonus characters include two digits. Word splitting yields 2 words: lib, 39. Median word length is 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lib39.ru

Page Load Overview

N/A
Total Load Time
N/A
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru
Text Length:9,859 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical62% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
62%
forum community discussion
56%
finance banking
49%
government public service
49%
news media journalism
42%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9151.101.65.229Fastly · CDNUnited States
AS54113Fastly, Inc.
687.250.250.119Russia
AS13238YANDEX LLC
6192.178.183.95Google · CDNUnited States
AS15169Google LLC
6109.237.1.36Kaliningrad, Kaliningrad Oblast, Russia
AS8774OOO Kompaniya Etype
6109.207.9.85Russia
AS196747Rostelecom
6104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6194.190.9.190Russia
AS52184Main Center of Information and Computing Ministry of culture of Russian Federation
07--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18BA3D6B08144787F8206969EF734AB5DF6F2907EEE560E12A2F409AE67D3D50CF5130A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:/l8L65dDi0vKg/V2wM10nZYJ1L3POXunX+gVRCSqgHJhaGUR41yigy:x5dj592wAVJRPNX9ThqohaGURu

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:106643:AGaxaBH4RBGACQJntDIWiQIiDSDQQZDgISAMYzYOESCEMqsoQ4ghisiHYMPqQwBBQX3IEACM5EjAY9UAsBkiAjMHQmphCBIB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0001000000ffffcb
Perceptual Hash:a912e8f551ec532d
Difference Hash:dd3b7bf0da2e263b
Wavelet Hash:008f091000ffffff
Color Hash:#ac5360

Scan History

Scan history not available

Unable to load historical scan data