Security Scan Report: virosh.com

Submitted: Nov 24, 2025, 8:57:53 AMCompleted: Nov 24, 2025, 9:00:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 19 IPs in 2 countries across 9 domains to perform 19 HTTP transactions. The main domain is virosh.com and was registered NaN years ago.

Submitted URL: https://virosh.com/wp-admin/[email protected]

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

High risk phishing site leveraging a compromised WordPress login page.

Risk Factors
Compromised WordPress site used for credential harvesting
Credential harvesting login form (email + password)
Hidden password field obscures user awareness
Brand impersonation on unrelated domain
Unranked domain despite being well‑established
Domain age information unavailable

Details

Page Title

Webmail Sign-in

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(30%)

Domain Information

The domain name 'virosh.com' uses the commercial generic top-level domain (.com). Count 6 characters in 'virosh' with two vowels and 4 consonants. Splitting it apart reveals 2 words: vi, rosh. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://virosh.com/wp-admin/signin.html?eta=malone@sekure.net

Page Load Overview

0.91s
Total Load Time
19
HTTP Requests
9
Domains
189 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:241 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical30% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.16.174.226United States
AS13335CLOUDFLARENET
268.178.163.30United States
AS26496AS-26496-GO-DADDY-COM-LLC
2142.250.185.202United States
AS15169GOOGLE
2142.250.186.99United States
AS15169GOOGLE
1142.250.184.228United States
AS15169GOOGLE
1104.26.12.205United States
AS13335CLOUDFLARENET
1172.67.74.152United States
AS13335CLOUDFLARENET
1178.63.16.224Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
1142.250.185.196United States
AS15169GOOGLE
1104.16.175.226United States
AS13335CLOUDFLARENET
1919--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T169236A3C6321C86D9DB35A3BFCA82B25D0149F53EDC9B7C8342D80862FE196A75187D9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:K6HQ060m/vPvyE42mgeivegeFf6yr1v4xaDRrdzH6M4sr4raXGrBinAr1kwztwsI:Y08XyK4FMAsEeboObg4g

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:46728:SQVBAANQSaAngKKQUCCsphawAyDQEUcREppknZlQAADEQmiCgEJkOC2UgRYxDGgAKMWAQrglKnISACCGopZwLQhNuSFAWMwt

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc3c3ffffffffff
Perceptual Hash:b13164cece9b9931
Difference Hash:0016160000000000
Wavelet Hash:fcc0c0fcf0f0f0f0
Color Hash:#bad22d

Other Hashes

Crop Resistant:0016160000000000

Scan History

Scan history not available

Unable to load historical scan data