Security Scan Report: cdn.winservers-network.com

Submitted: Sep 13, 2026, 1:47:48 PMCompleted: Sep 13, 2026, 1:48:10 PMpubliccompleted

Summary

This website contacted 2 IPs in 1 country across 1 domain to perform 1 HTTP transaction. The main domain is cdn.winservers-network.com and was registered 2 years 5 months ago.

Submitted URL: https://cdn.winservers-network.com

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Primary and parent domains are flagged as Cobalt Strike malware/C2 infrastructure by multiple threat-intel feeds; the only content served is a Cloudflare 521 error page, so the host is malicious regardless of the empty page.

Risk Factors
Multi-source corroborated Cobalt Strike (cobaltstrike-2) malware/C2 indicator on the scanned primary domain
Malware indicator on the parent/related domain winservers-network.com
Host unreachable (Cloudflare 521), consistent with dormant or torn-down malicious infrastructure
Domain age information unavailable

Details

Page Title

winservers-network.com | 521: Web server is down

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(76%)

Domain Information

The domain name 'cdn.winservers-network.com' uses the commercial generic top-level domain (.com) and includes subdomain 'cdn'. Count 18 characters in 'winservers-network' split between five vowels and 12 consonants, notching 1 hyphen. Word splitting yields three words: win, servers, network. Median word length is seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cdn.winservers-network.com

Page Load Overview

1.12s
Total Load Time
8
HTTP Requests
1
Domains
19 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:708 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical76% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
76%
technology software
67%
government public service
51%
cryptocurrency blockchain
45%
news media journalism
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Page Statistics

8
Requests
1
Unique Domains
23.1 KB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T126E16672B1B5127700A381923695FB697AE0C613CBEF55D8B3DCC2632F9EE81D903294

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ljHjDju4Ba/CqE49eb4S4BuRVO/Q85yFO3I4YeJ:ja/CqEJxh0IwyFO3IzeJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7005:AyBgRRgBDAoUIQIWAABBAAqHAzB9cEFAAwRACqi7JIQGYChAhQqUgekTGCJIQcgCBIGHwxUoEIPA6I6wAJAUAEAEJCAEggCA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c70000d7f7ffff
Perceptual Hash:b4389abc9a676531
Difference Hash:1c3e8e8a3406061c
Wavelet Hash:c7000000d7f3f7ff
Color Hash:#d22dd2

Other Hashes

Crop Resistant:1c3e8e8a3406061c

Scan History

Scan history not available

Unable to load historical scan data