Security Scan Report: kolesa.dp.ua

Site favicon
Submitted: Oct 7, 2026, 11:22:31 AMCompleted: Oct 7, 2026, 11:23:43 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 76%

8
Risk Score

Content is a genuine Ukrainian tire retailer, but IDS detected CRITICAL ET MALWARE ClickFix/EtherHiding activity and script fetches to unrelated blockchain RPC nodes — likely a compromised site serving malware.

Risk Factors (3)
CRITICAL IDS malware alerts (ET MALWARE ClickFix / EtherHiding Exfil) indicating malicious activity on the rendered page
Page makes fetch requests to blockchain RPC nodes that have no legitimate purpose for a tire shop, matching EtherHiding malware behaviour
Third-party blockchain RPC hosts appear in unverified threat-intel 'known attacker' feeds
Domain age information unavailable

Details

Page Title

Різноширокі шини - купити різношироку гуму в Дніпрі | Kolesa.dp.ua

Scan Type

public

Domain Name Analysis

The domain 'kolesa.dp.ua' uses the Ukrainian country-code top-level domain (.dp.ua) with no subdomain. The registrable portion 'kolesa' spans 6 characters containing three vowels alongside three consonants. Tokenizing the label suggests 2 words: kol, esa. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kolesa.dp.ua/wide-tires

Page Load Overview

14.03s
Total Load Time
5.5 MB
Total Size

Language Analysis

Primary Language

🇺🇦Ukrainian
Code: uk
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:uk
Text Length:8,315 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate business70% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
70%
government public service
65%
documentation technical
60%
adult content
40%
news media journalism
30%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2288.198.16.15Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
4142.251.153.119Google · CDNUnited States
AS15169Google LLC
4142.251.110.97Google · CDNUnited States
AS15169Google LLC
4142.251.20.94Google · CDNUnited States
AS15169Google LLC
4172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.66.146.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
435.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
445.91.130.36Ukraine
AS205722Binotel LLC
4216.239.34.36Google · CDNUnited States
AS15169Google LLC
4142.251.127.157Google · CDNUnited States
AS15169Google LLC
13028--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C7F3E95166F044664457E1D6EA25AE0CF8A6403FF6434B05B26C67E93FC3E24EA3363E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:sk3SUQacI/+5GgV5QwS6JVnJhC9Cbo+xRF:sracI2VrbG9Cp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:164083:MBQkUAgEACpARANCiMQxTEg4hwAUIc1ZESsGCoCEWMIIkCYikCQTEIWHwJdlI9PpJ46CBgNUTGSgGKASSABQEIgEBhuJY8GQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffdf899981c3e7ff
Perceptual Hash:bf1894666fc29469
Difference Hash:233e33332b270b38
Wavelet Hash:838f81998183e7bf
Color Hash:#785b3a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data