Security Scan Report: old.r.nf

Submitted: May 10, 2026, 5:43:30 PMCompleted: May 10, 2026, 5:44:42 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 6 HTTP transactions. The main domain is old.r.nf and was registered NaN years ago.

Submitted URL: https://old.r.nf

AI Security Verdict

High Risk

Confidence: 88%

10
Risk Score

Site shows no user‑facing forms but triggers several critical IDS alerts for large POST data exfiltration, indicating malware activity; classify as high‑risk malware distribution.

Risk Factors
Multiple critical IDS alerts indicating possible malware data exfiltration
Unranked domain reputation despite long age
High number of eval() calls in JavaScript
Domain age information unavailable

Details

Primary Scan Blocked — Fallback Capture Shown

The primary scanner could not load this page (possible bot protection). The screenshot and page details shown were captured by a fallback browser that loaded the page successfully.

Page Title

Just a moment...

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(78%)

Domain Information

The domain name 'old.r.nf' uses the .nf country-code top-level domain; it also runs on subdomain 'old'. The core label 'r' covers 1 characters containing 0 vowels alongside 1 consonant. It segments into 1 word: r. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://old.r.nf

Page Load Overview

0.36s
Total Load Time
13
HTTP Requests
2
Domains
3 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:370 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software78% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
78%
documentation technical
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7172.67.155.174United States
AS13335Cloudflare, Inc.
6104.18.95.41United States
AS13335Cloudflare, Inc.
132--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A9E2D723AE54122F3113C79DB790F584A3356A018F1AB377F56553B49F8D1AE2A2338B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:cxzFqvLh8Oh8XMVk9vjaKObveaIFEmLJkPZCLa3+ZEEyh6tFG:IwDmsSaKObveaIFEmLJkPZCLPmKG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33751:EBXk8oCWSyFAgF5AIXBhxlQxEQJesgAXgDQHIoAGMMoSIIMSUgETUNAFgCBOQEqyp6gAAUABCABi6IUBLZFCAJA9gUDgAgSp

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3c7c3c3c7ff
Perceptual Hash:b418cecdc3c46667
Difference Hash:201c161c1e161608
Wavelet Hash:fec6c2c6c2c2c2e6
Color Hash:#3a2d86

Other Hashes

Crop Resistant:201c161c1e161608

Scan History

Scan history not available

Unable to load historical scan data