Security Scan Report: killbot.ru

Site favicon
Submitted: Sep 28, 2026, 1:06:34 PMCompleted: Sep 28, 2026, 1:07:07 PMpubliccompleted

This website contacted 7 IPs in 2 countries across 12 domains to perform 41 HTTP transactions. The main domain is killbot.ru and was registered 29 years ago.

Submitted URL: https://killbot.ru

The Cisco Umbrella rank of the primary domain is #735,572 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 60%

2
Risk Score

Established 28-year-old domain serving its own KillBot anti-bot verification interstitial; no forms, no impersonation, no malware. Only a generic abuse-reputation tag on a subdomain, which adds no content risk.

Risk Factors (3)
Inline scripts use encoding/decoding functions and 33 crypto API calls, typical of bot-fingerprinting challenges
Cross-origin POST to r1.killbot.ru/c.php carrying a campaign token
Seven cross-domain redirects before landing
Safety Factors (5)
Domain age 28 years — well-established, minimal age risk
Zero credential, password, or payment fields (verified from captured DOM)
No YARA malware patterns, no known malicious kit, no Safe Browsing hit
No brand impersonation; page presents its own 'KillBot' service identity
Third-party script hosts are ranked top-1M and the observed analytics (Yandex Metrica, Mail.ru privacy) are legitimate
Domain age information unavailable

Details

Page Title

User verification...

Scan Type

public

Domain Name Analysis

You're looking at domain 'killbot.ru' on the Russian country-code top-level domain (.ru) while skipping any subdomain. Its registrable label 'killbot' stretches across 7 characters containing two vowels alongside five consonants. Word splitting yields 2 words: kill, bot. The median word length lands at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://killbot.ru

Page Load Overview

0.70s
Total Load Time
238 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:626 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software83% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
83%
e-commerce shopping
70%
documentation technical
69%
government public service
42%
news media journalism
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11111.88.217.99Moscow, Moscow, Russia
AS50340JSC Selectel
577.88.21.119Yandex · CLOUDMoscow, Moscow, Russia
AS13238YANDEX LLC
5190.115.31.218United Arab Emirates
AS59692IQWeb FZ-LLC
587.250.251.119Yandex · CLOUDRussia
AS13238YANDEX LLC
587.250.250.119Yandex · CLOUDRussia
AS13238YANDEX LLC
590.156.233.120Russia
AS47764LLC VK
590.156.232.15Russia
AS47764LLC VK
417--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C1B3DA9985B3243644373079EBBF754D36B180039005DA73BC5D8966EFD0A3A8AF5BE8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:B/CxmMCuooQoVqluT7fxcJWwZ8h9MYe/vFdiVa/aLV6E4fY:BYVoJL0T7fxcgw7dzaLqfY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:114195:h28QNjAcUQUAYspiQCgQAAAKCAKFlQXIAigLQAigxAA4UYOEEkMDimAMwgVQHAQCUgfJLAZGMQzLIExhOuQIgkAAxQBSJUCA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffe7
Perceptual Hash:b399cc8c3333cccc
Difference Hash:0000000808000008
Wavelet Hash:0c0c3c24273f3f27
Color Hash:#4d783a

Other Hashes

Crop Resistant:0000000808000008

Scan History

Scan history not available

Unable to load historical scan data