Security Scan Report: mx1.prod.rossko.su

Submitted: Oct 4, 2026, 11:40:33 AMCompleted: Oct 4, 2026, 11:41:16 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Fake 'confirm access' ClickFix page: it stages an encoded PowerShell command on the clipboard and instructs Win+R/Ctrl+V execution, delivering a malware downloader. Confirmed by CRITICAL IDS and malicious Indicators of Compromise.

Risk Factors (6)
Fake CAPTCHA / 'verify you are human' social-engineering lure (text: 'Документ готов к просмотру - ID:8913')
Windows shell command staged in obfuscated (-enc) PowerShell form inside page JavaScript
Clipboard hijacking (pastejacking) that silently plants the command for the user to paste into Win+R
Payload fetched from a third-party .su host (buh.reallstbank.ru/payload/run.ps1) — external malware staging
Indicators of Compromise: malicious 'ek clearfake-1' report on the scanned domain and on rossko.su
Fabricated reCAPTCHA branding on a non-Google domain with no legitimate document service behind it
Domain age information unavailable

Details

Page Title

Подтверждение доступа

Scan Type

public

Domain Name Analysis

Domain 'mx1.prod.rossko.su' uses the .su country-code top-level domain with subdomain 'mx1.prod'. The registrable portion 'rossko' spans 6 characters containing two vowels alongside 4 consonants. Splitting it apart reveals 2 words: ross, ko. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mx1.prod.rossko.su/

Page Load Overview

4.33s
Total Load Time
6 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru
Text Length:360 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service39% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
39%
adult content
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
295.163.227.93Russia
AS197695Domain names registrar REG.RU, Ltd
1142.251.127.94Google · CDNUnited States
AS15169Google LLC
32--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0F143321AB300616A2794A9AB53EF0637319023E955CA797EDC1544CFCEE91EAF335C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:YqDxt5854wr6EsjdTvt9vL+xTM5/L8iIBRDDV6B2qbcA2IJCxgqq1azq9y2hMiWL:MrkCFGL9HhMiWhiw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7750:mAFGdERICQBNX6IKQ6QAEO7U2pIFlBCI2gAZGCEAgCAQAIiVMAJGQ8izgotGICMAmBIIGCAADDIDhGCIkBQCmiZENABEAaKc

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e664999b66649993
Difference Hash:0000000c0c000000
Wavelet Hash:0f0f0f07070f0f0f
Color Hash:#86802d

Other Hashes

Crop Resistant:0000000c0c000000

Scan History

Scan history not available

Unable to load historical scan data