Security Scan Report: vr.znbbmwq.com

Submitted: Sep 26, 2026, 12:45:05 AMCompleted: Sep 26, 2026, 12:45:42 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 76%

7
Risk Score

New unranked domain posing as an Adobe PDF viewer/installer, using fake 'update Adobe Reader' prompts, honeypot fields and redirects. No credential forms, but clear Adobe brand abuse and a fake software download lure.

Risk Factors
Impersonation of Adobe on a non-Adobe, newly registered, unranked domain
Fake 'secure PDF requires Adobe update' social-engineering lure with an installer download path
Honeypot/challenge fields indicating automatically generated scam page
Device restriction gate redirecting users to browser installers
Multiple cross-domain redirects
Domain age information unavailable

Details

Page Title

PDF Viewer

Scan Type

public

Domain Name Analysis

The domain name 'vr.znbbmwq.com' uses the commercial generic top-level domain (.com) and includes subdomain 'vr'. Count 7 characters in 'znbbmwq' containing zero vowels alongside 7 consonants. Tokenizing the label suggests four words: zn, b, bmw, q. Average segment length settles at 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://vr.znbbmwq.com/inv/Adobe_Installer.html

Page Load Overview

2.70s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:943 chars
Detector Agreement:100%

Website Classification

Primary Category

other31% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

other
31%
e-commerce
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.247.177.79Phoenix, Arizona, United States
AS31898Oracle Corporation
1172.67.68.67Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.152.119Google · CDNUnited States
AS15169Google LLC
1142.250.154.147Google · CDNUnited States
AS15169Google LLC
1142.250.154.106Google · CDNUnited States
AS15169Google LLC
1142.251.151.119Google · CDNUnited States
AS15169Google LLC
1142.251.157.119Google · CDNUnited States
AS15169Google LLC
1192.178.183.105Google · CDNUnited States
AS15169Google LLC
1142.251.14.106Google · CDNUnited States
AS15169Google LLC
1142.251.14.104Google · CDNUnited States
AS15169Google LLC
1311--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12FB5D81B8D0F56A07F3828BF4B8BA6497010F79395C39794F0DF4C9DF64AE1A264926C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24576:jz+EHVWfOTQ3AXuT8+o7rjyHlnxXuT8+o7rHXuT8+o7rly2lnm:e5fWXS8+Q3MlnxXS8+QrXS8+Q5Rlnm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2285075:AJqllQZnMcBItaqmVCAACHCABjChREAilCMCWCQCBQGI9AkwRAAyBBEz6AoFMEQKZ4xqgqA2KAAkWSODz2CBESlUTIVggBmg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9c9c8c9c9c9c1c1c
Perceptual Hash:9e7701dd6d656700
Difference Hash:31393d3d3939b9b1
Wavelet Hash:9d9c9c9c9c9c1c1d
Color Hash:#5e40bf

Scan History

Scan history not available

Unable to load historical scan data