Security Scan Report: dms.cabinet-ingos.ru

Submitted: Oct 4, 2026, 12:33:56 PMCompleted: Oct 4, 2026, 12:34:40 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Compromised host serving a ClickFix lure: fake 'document verification' page copies a base64-encoded PowerShell/curl payload to the clipboard and tells the victim to paste it into Windows Run. CRITICAL IDS malware alert — do not press Win+E / paste anything.

Risk Factors (4)
Clipboard shell injection (pastejacking) staging an encoded Windows command
Encoded/obfuscated remote payload fetch (curl/PowerShell to an external host) hidden in page script
CRITICAL Suricata malware alert for encoded PowerShell command
Social-engineering 'verify to view document' / fake reCAPTCHA workflow directing user to Windows Run/Explorer execution
Domain age information unavailable

Details

Page Title

Подтверждение доступа

Scan Type

public

Domain Name Analysis

The domain 'dms.cabinet-ingos.ru' uses the Russian country-code top-level domain (.ru), featuring subdomain 'dms'. The registrable portion 'cabinet-ingos' spans 13 characters containing five vowels alongside seven consonants, along with 1 hyphen. Tokenizing the label suggests three words: cabinet, in, gos. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dms.cabinet-ingos.ru/

Page Load Overview

2.94s
Total Load Time
6 KB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:80%
Script:Cyrillic
Direction:ltr

Detection Details

HTML Lang Attribute:ru
Text Length:360 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service38% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
38%
adult content
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
295.163.227.93Russia
AS197695Domain names registrar REG.RU, Ltd
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
32--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0F143321AB300616A2794A9AB53EF0637319023E955CA797EDC1544CFCEE91EAF335C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:YqDxt5854wr6EsjdTvt9vL+xTM5/L8iIBRDDV6B2qbcA2IJCxgqq1azq9y2hMiWL:MrkCFGL9HhMiWhiw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7750:mAFGdERICQBNX6IKQ6QAEO7U2pIFlBCI2gAZGCEAgCAQAIiVMAJGQ8izgotGICMAmBIIGCAADDIDhGCIkBQCmiZENABEAaKc

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e664999b66649993
Difference Hash:0000000c0c000000
Wavelet Hash:0f0f0f07070f0f0f
Color Hash:#23931f

Other Hashes

Crop Resistant:0000000c0c000000

Scan History

Scan history not available

Unable to load historical scan data