Security Scan Report: lemon.trueforceteam.ru

Submitted: Mar 31, 2026, 3:30:10 PMCompleted: Mar 31, 2026, 3:31:24 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is lemon.trueforceteam.ru.

Submitted URL: https://lemon.trueforceteam.ru/oyzy4kx8fjoz.html

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Domain is flagged by multiple Indicators of Compromise and high‑severity IDS alerts; treat as confirmed credential‑phishing scam.

Risk Factors
Malicious primary domain indicator (Unknown Stealer) on lemon.trueforceteam.ru
Related malicious domain indicator (Unknown Stealer) on trueforceteam.ru
High‑severity network IDS alert (Spamhaus DROP listed traffic)
Critical JavaScript obfuscation patterns (base64, unescape, concatenation)
Page title "Sign In" on a known malicious domain suggests credential harvesting
Domain age information unavailable

Details

Page Title

lemon.trueforceteam.ru

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(74%)

Domain Information

The domain name 'lemon.trueforceteam.ru' uses the Russian country-code top-level domain (.ru) with subdomain 'lemon'. Count 13 characters in 'trueforceteam' with 6 vowels and seven consonants. Word splitting yields three words: true, force, team. The median word length lands at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lemon.trueforceteam.ru/oyzy4kx8fjoz.html

Page Load Overview

0.93s
Total Load Time
3
HTTP Requests
2
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:52,683 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain74% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
74%
healthcare medical
71%
news media journalism
71%
technology software
65%
finance banking
62%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
391.92.243.119New York, New York, United States
AS202412Omegatech LTD
31--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CB048F77329A063986558498F05B43099F20B143F506C9BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:LfQho9PKBb9Js3q9Jzbs6tlg3SBKwdQWgceIszi2bMy8OldO:0hoC9JSqzzbs6o3Sj3gcrsu2eA4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184552:CkgAJUAEJcq6wKIQHgBYp5S2Ug0WDjECIRAVKicAQHYsYwBTgRJw/7AAIIEgqRXEmQLMIgyRERXACFaAjApEIahFoz0AMEoh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3c7ffffffff
Perceptual Hash:b131cccccc673363
Difference Hash:00180c1400000000
Wavelet Hash:3c1c000cf0f0f0f0
Color Hash:#1f5b93

Other Hashes

Crop Resistant:00180c1400000000

Scan History

Scan history not available

Unable to load historical scan data