Security Scan Report: remus.su

Redirected to:
https://usrlnk.io/remus
Submitted: Sep 14, 2026, 9:47:32 PMCompleted: Sep 14, 2026, 9:47:53 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Multi-feed malware IoC (lummac2) on remus.su plus threat-actor landing content ('actual links', exploit.im contact) and HIGH IDS alerts for .su traffic — avoid and report.

Risk Factors (4)
Multi-source corroborated malware IoC (lummac2) on the primary domain
Page advertises 'actual links', support and purchase channels via exploit.im Jabber contact typical of threat-actor operations
Multi-hop cross-domain redirect from remus.su to usrlnk.io masking the true host
HIGH-severity IDS alerts for .su TLD traffic associated with malware
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the .su country-code top-level domain, 'remus.su' is registered. The registrable portion 'remus' spans 5 characters split between 2 vowels and 3 consonants. Word splitting yields 1 word: remus. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://remus.su

Page Load Overview

4.83s
Total Load Time
252 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:60%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:227 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ru

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
295.163.244.136Russia
AS197695Domain names registrar REG.RU, Ltd
2188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.95Google · CDNUnited States
AS15169Google LLC
84--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D0F0DC43A8A1842E123057806CD0F81C0D8AEB578606AE40B8E7A0BD5FD4E82CC9F878

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:h4hqIY7YOLBrAMMJAzy29fAbpliLDe1jLnpAVAqIbR2+MvfWHwl9NV4LKTj+Gwlf:hRo6KyLSLpAqqsKWWNV7lqAEd1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:9e673df06e77e1415d1ced0f89a0e924

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefcf8f8f0e0c080
Perceptual Hash:ddb033ccccb324cc
Difference Hash:0000000000000000
Wavelet Hash:fcfcf8f8f0e0c080
Color Hash:#2dc7d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data