Security Scan Report: rxtv.ru

Redirected to:
https://www.rxtv.ru/
Site favicon
Submitted: Sep 19, 2026, 8:24:13 AMCompleted: Sep 19, 2026, 8:26:13 AMpubliccompleted

This website contacted 146 IPs in 14 countries across 136 domains to perform 789 HTTP transactions. The main domain is rxtv.ru and was registered 9 years ago.

Submitted URL: https://rxtv.ru

Effective URL:

https://www.rxtv.ru/
Redirected

AI Security Verdict

High Risk

Confidence: 70%

7
Risk Score

Long-established Russian TV listings site, but page loads a malicious 'wp inject' resource and triggers a CRITICAL phishing OAuth-redirect IDS alert amid 8 cross-domain redirects — signs of compromise/injection.

Risk Factors
CRITICAL phishing/OAuth-redirect IDS alert tied to the page load
Malicious external script resource (a11ybar.com, 'wp inject') injected into the page
Excessive cross-origin redirect chain (8 redirects, 4 cross-domain)
Runtime code generation via Function() constructor
Domain age information unavailable

Details

Page Title

Программа передач на сегодня - телепрограмма на все тв каналы

Scan Type

public

Domain Name Analysis

You're looking at domain 'rxtv.ru' on the Russian country-code top-level domain (.ru) and has no subdomain. Its registrable label 'rxtv' stretches across 4 characters holding 0 vowels versus four consonants. Tokenizing the label suggests 3 words: r, x, tv. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rxtv.ru

Page Load Overview

75.17s
Total Load Time
13.6 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:74%
Script:Cyrillic
Direction:ltr

Detection Details

Text Length:5,933 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media99% confidence
Type: spa
Method: ml+structural

All Detected Categories

entertainment media
99%
news media journalism
86%
adult content
68%
government public service
65%
real estate property
62%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
642.56.245.66Frankfurt am Main, Hesse, Germany
AS213250ITP-Solutions GmbH & Co. KG
5104.21.27.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.132.202.70Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
5172.67.142.245Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.20.157Google · CDNUnited States
AS15169Google LLC
5142.251.20.156Google · CDNUnited States
AS15169Google LLC
595.216.65.102Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
587.250.250.119Yandex · CLOUDRussia
AS13238YANDEX LLC
588.212.202.52Moscow, Moscow, Russia
AS39134Edinaya Set Limited Liability Company
5142.250.154.139Google · CDNUnited States
AS15169Google LLC
789146--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B82101A3490A980B6202D113CC91B64CF99B46FFBE9E49A67CD128FF75D16B8817015F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hMCC0sPGAWxgdA1PNKEqxfHGxejfEmwSEZACtQ7PxptPEvq6A2+s0oa:6NzEqUKbWUN+nn0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1404:AAAAACEEQAAAAiAAAAAAAEAQAAAAgAKAIAAAAEAAAAgAAkAAAAAAQAgAAAIAAAIAAAAAAADRAAAAoAACCIAAAQQACAAAAACA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00dfffffffffdfff
Perceptual Hash:b8313c66474f474b
Difference Hash:861c500000203202
Wavelet Hash:00023e3efefe007e
Color Hash:#69ac53

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data