Security Scan Report: realdolmen.gallery.vsassets.io

Site favicon
Submitted: May 6, 2026, 4:37:26 AMCompleted: May 6, 2026, 4:38:42 AMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 3 countries across 18 domains to perform 47 HTTP transactions. The main domain is realdolmen.gallery.vsassets.io and was registered NaN years ago.

Submitted URL: https://realdolmen.gallery.vsassets.io

The Cisco Umbrella rank of the primary domain is #11,701 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 82%

7
Risk Score

The site hosts highly obfuscated JavaScript and triggers critical IDS alerts for data exfiltration and C2 activity, indicating malware distribution despite a legitimate Microsoft subdomain.

Risk Factors
Critical network IDS alerts suggesting malware activity and command‑and‑control communication
Highly obfuscated JavaScript with suspicious static analysis patterns
Multiple external CDN domains referenced
Domain age information unavailable

Details

Page Title

Extensions for Visual Studio family of products | Visual Studio Marketplace

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(81%)

Domain Information

Domain 'realdolmen.gallery.vsassets.io' uses the British Indian Ocean Territory country-code top-level domain (.io) and includes subdomain 'realdolmen.gallery'. Its registrable label 'vsassets' stretches across 8 characters holding two vowels versus 6 consonants. It segments into 2 words: vs, assets. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://realdolmen.gallery.vsassets.io

Page Load Overview

4.44s
Total Load Time
142
HTTP Requests
19
Domains
937 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:1,781 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software81% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
81%
documentation technical
45%
corporate
25%
phishing/scam
20%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
23184.24.77.39Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
1720.86.88.94Amsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
172.19.198.35Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
17150.171.74.16United States
AS8075Microsoft Corporation
1723.32.239.64Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
1723.48.23.26Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
17184.24.77.25Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
17150.171.109.101United States
AS8075Microsoft Corporation
1428--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12B04D824B4F9013386AB93E6F1B49F56EEE5F30BC5434540B4AC8A602FD7D51E85B82E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:d9wvYad+yMZLxnL///u////w///8////d////E////M///6////2////o///z//E:42///u////w///8////d////E////M/5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:190144:sAIFfIAjhkBhWJCiB0kCFSIM0HwQMwCQCYPSRBkROwgEkRFhYGIlk4gDmCfEJKSBkBAyI1QOLykFCvgCAoCJxrChlESCzCoA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff7f7fffdfcfcf07
Perceptual Hash:b8c736d807d827d8
Difference Hash:80c0d080b4b4303d
Wavelet Hash:0e0e0e4e0e8e8e00
Color Hash:#5d1f93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data