Security Scan Report: cq210804-wordpress-h7agx.tw1.ru

Redirected to: https://vh456.timeweb.ru/blocked/?ref=cq210804-wordpress-h7agx.tw1.ru#19de5f8683c787d0f

Submitted: Nov 22, 2025, 8:19:32 PMCompleted: Nov 22, 2025, 8:23:31 PMpubliccompleted
Loading additional data...

Summary

This website contacted 20 IPs in 3 countries across 11 domains to perform 51 HTTP transactions. The main domain is vh456.timeweb.ru.

Submitted URL: https://cq210804-wordpress-h7agx.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#19de5f8683c787d0f

Effective URL: https://vh456.timeweb.ru/blocked/?ref=cq210804-wordpress-h7agx.tw1.ru#19de5f8683c787d0fRedirected

The Cisco Umbrella rank of the primary domain is #163,229 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 70%

5
Risk Score

Suspicious blocked WordPress site; treat as potentially malicious.

Risk Factors
Compromised WordPress site path suggests possible malicious use
Domain blocked by hosting provider indicates prior abuse
Low ranking and likely new domain increase suspicion
Domain age information unavailable

Details

Page Title

Домен заблокирован в Timeweb

Scan Type

public

Language

🇷🇺

Russian

(60% confidence)

Category

corporate business

(44%)

Domain Information

Domain 'cq210804-wordpress-h7agx.tw1.ru' uses the Russian country-code top-level domain (.ru); it also runs on subdomain 'cq210804-wordpress-h7agx'. The registrable portion 'tw1' spans 3 characters split between zero vowels and two consonants, along with one digit. Word splitting yields 2 words: tw, 1. Average segment length settles at 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cq210804-wordpress-h7agx.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#19de5f8683c787d0f

Page Load Overview

1.25s
Total Load Time
51
HTTP Requests
11
Domains
1.3 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:60%
Script:Cyrillic
Direction:ltr

Detection Details

Language Code:ru
Detection Confidence:60%
Script Type:Cyrillic
HTML Lang Attribute:en
Text Length:1,736 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ru

Website Classification

Primary Category

corporate business44% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
44%
technology software
37%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1492.53.96.141Russia
AS9123Jsc timeweb
877.88.21.119Russia
AS13238YANDEX LLC
8142.250.186.99United States
AS15169GOOGLE
737.9.64.225Russia
AS13238YANDEX LLC
387.250.251.119Russia
AS13238YANDEX LLC
287.250.250.119Russia
AS13238YANDEX LLC
277.88.55.88Russia
AS13238YANDEX LLC
25.255.255.77Russia
AS13238YANDEX LLC
22a02:6b8:23::225Russia
AS13238YANDEX LLC
22a00:1450:4001:81c::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
5120--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16163C7E701F0D0E14A4FC3B19D365A9B9D7624BFDE81928479DC0A507F92DF58883AAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:kHfGeFKP7VuidqCHG0PxiHm/ouVHHMjEENRzigLIN0:kHf5GBuidqCHG0AupMVbLIG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:72932:EEwAKDQmABwDCNgZIIAHFlQQs3IhBEJEk4zpWkVSlwDWEIYASpUDaAAIUEgWgQN0AfAmfMHgKIAYUFxATgEUCgCwU0gADwyA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:818181ffffffffff
Perceptual Hash:ba3b3ac0c5c5c5c5
Difference Hash:2b2b0b36f0c0b8e8
Wavelet Hash:000000007f7fffff
Color Hash:#1f9372

Scan History

Scan history not available

Unable to load historical scan data