Security Scan Report: kxx.pp.ua

Redirected to:
https://kxx.pp.ua/
Submitted: Oct 19, 2025, 6:33:28 AMCompleted: Oct 19, 2025, 6:34:31 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 1 domain to perform 9 HTTP transactions. The main domain is kxx.pp.ua and was registered NaN years ago.

Submitted URL: http://kxx.pp.ua/

Effective URL: https://kxx.pp.ua/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Site impersonates Cloudflare, has malicious primary domain and circular redirects – confirmed scam.

Risk Factors
Malicious primary domain Indicator of Compromise
Circular redirect loop
Brand impersonation of Cloudflare on an unrelated domain
UNRANKED/low‑reputation domain presenting a major brand
Domain age information unavailable

Details

Page Title

Cloudflare DNS管理系统

Scan Type

public

Language

🇨🇳

Chinese

(80% confidence)

Category

technology software

(91%)

Domain Information

The domain 'kxx.pp.ua' uses the Ukrainian country-code top-level domain (.ua), featuring subdomain 'kxx'. Its registrable label 'pp' stretches across 2 characters split between 0 vowels and two consonants. Splitting it apart reveals one word: pp. 'pp' most strongly signals Sinhala. Secondary signals appear in Danish and English. Overall, 'kxx.pp.ua' reads as Sinhala with single-word simplicity.

Screenshot

Security scan screenshot of http://kxx.pp.ua/

Page Load Overview

40.98s
Total Load Time
9
HTTP Requests
1
Domains
221 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:80%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:80%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:235 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software91% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
91%
documentation technical
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.21.69.42United States
AS13335CLOUDFLARENET
2172.67.204.82United States
AS13335CLOUDFLARENET
22606:4700:3033::ac43:cc52United States
AS13335CLOUDFLARENET
22606:4700:3032::6815:452aUnited States
AS13335CLOUDFLARENET
94--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E3D2631D45F321A66853E0782BBB578A2764D407CC0BCE1D7BDE27848F86B94ADD3B48

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:IgApr8hQOlZP7nSym3DUkD/DqxD0U1qH43vyoR6O5uE7qBODEnERURKM4XaZqRK/:I1SeT7E9k2wTF3zqX1AJw+taw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28755:BAE4qGIAoAEGEsIJQABgDAjh5NUARAwnQCGfhIgahCmpQAokCIiAOOARO+BsaKGACg2QCImTDQmg4RgEAkECBCQMM4EQgEoR

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:40000e6e7efce0e0
Perceptual Hash:d0296f92d1695ab5
Difference Hash:9cecf8989cc88280
Wavelet Hash:40030f7ffeece0e0
Color Hash:#53ac8d

Other Hashes

Crop Resistant:9cecf8989cc88280

Scan History

Scan history not available

Unable to load historical scan data