Security Scan Report: rb-otoplenie.ru

Redirected to: blob:https://rb-otoplenie.ru/02e1b0b1-af13-464a-9750-722cc2c44e2c

Submitted: Oct 4, 2025, 10:13:17 AMCompleted: Oct 4, 2025, 10:13:46 AMpubliccompleted
Loading additional data...

Summary

This website contacted 13 IPs in 3 countries across 3 domains to perform 8 HTTP transactions. The main domain is .

Submitted URL: https://rb-otoplenie.ru/wp-includes/customize/class-wp-customize-partial.html

Effective URL: blob:https://rb-otoplenie.ru/02e1b0b1-af13-464a-9750-722cc2c44e2cRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site impersonating Capital One; avoid interaction and report.

Risk Factors
Brand impersonation
Disguised password fields
Unicode evasion
New or unknown domain age
Unranked in Cisco Umbrella
Domain age information unavailable

Details

Page Title

Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(61%)

Domain Information

The domain 'rb-otoplenie.ru' uses the Russian country-code top-level domain (.ru). The registrable portion 'rb-otoplenie' spans 12 characters with five vowels and 6 consonants, along with one hyphen. Segmentation suggests four words: rb, ot, ople, nie. Median word length comes out to 2.5 characters. 'ot' most often appears in Polish. You may catch it in Afrikaans and Dutch as well.

Screenshot

Security scan screenshot of https://rb-otoplenie.ru/wp-includes/customize/class-wp-customize-partial.html

Page Load Overview

4.19s
Total Load Time
8
HTTP Requests
3
Domains
30 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,433 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking61% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
61%
adult content
47%
social media network
44%
government public service
41%
documentation technical
37%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8151.101.66.137San Francisco, California, United States
AS54113FASTLY
063.176.8.218Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
035.157.26.135Frankfurt am Main, Hesse, Germany
AS16509AMAZON-02
091.201.52.229Russia
AS44128Internet-Pro LLC
0151.101.2.137UnknownUnknown
02a05:d014:58f:6200::259UnknownUnknown
02a04:4e42:600::649UnknownUnknown
02a04:4e42:400::649UnknownUnknown
0151.101.130.137UnknownUnknown
02a05:d014:58f:6200::258UnknownUnknown
813--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12443543661A341BADDB3CAC847EB2A463E849887E0C9D12477AC9AD44F838D5D47D3DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:e7FSF3FuWFzF+fs8utovi8utovWX9ssTHdrCt1WtcL/plyA7qvE6mw:0Ql0WxMTv9vHeNCt1WtcLRlyA7q86mw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57008:gIgBAwEEhgpAIQCtFBBkEkoOCLCBFgjQqQjHAMzwpChCBBtDHMiiSMgYI6AhAMICQEKEK8AoygCRBxYEDQwVgEISQg0kyDQE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fa5bde7c3ffcfff
Perceptual Hash:b38f8c27239d89b1
Difference Hash:e869704c4d2a2c00
Wavelet Hash:7f343c2c0424df0d
Color Hash:#1f932f

Other Hashes

Crop Resistant:e869704c4d2a2c00

Scan History

Scan history not available

Unable to load historical scan data