Security Scan Report: cf535265-wordpress-00986.tw1.ru

Redirected to: https://vh454.timeweb.ru/blocked/?ref=cf535265-wordpress-00986.tw1.ru

Site favicon
Submitted: Oct 15, 2025, 5:12:01 PMCompleted: Oct 15, 2025, 5:12:46 PMpubliccompleted
Loading additional data...

Summary

This website contacted 24 IPs in 3 countries across 10 domains to perform 43 HTTP transactions. The main domain is vh454.timeweb.ru.

Submitted URL: https://cf535265-wordpress-00986.tw1.ru/wp-content/plugins/nwca-ddcanw/pages/region.php?lca#ee6837ee2e3f31b3c

Effective URL: https://vh454.timeweb.ru/blocked/?ref=cf535265-wordpress-00986.tw1.ruRedirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Site shows URL manipulation and compromised WordPress indicators; treat as high‑risk phishing.

Risk Factors
URL manipulation (high‑risk phishing technique)
Compromised WordPress site used for redirect
Unranked/low‑reputation domain
Potentially brand‑impersonating redirect without legitimate brand verification
Domain age information unavailable

Details

Page Title

Домен припаркован в Timeweb

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain 'cf535265-wordpress-00986.tw1.ru' uses the Russian country-code top-level domain (.ru) with subdomain 'cf535265-wordpress-00986'. Count 3 characters in 'tw1' split between zero vowels and two consonants, plus 1 digit. Segmentation suggests 2 words: tw, 1. Median word length comes out to 1.5 characters. 'tw' most strongly signals Albanian.

Screenshot

Security scan screenshot of https://cf535265-wordpress-00986.tw1.ru/wp-content/plugins/nwca-ddcanw/pages/region.php?lca#ee6837ee2e3f31b3c

Page Load Overview

26.97s
Total Load Time
43
HTTP Requests
10
Domains
885 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,802 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
20142.250.185.234United States
AS15169GOOGLE
1142.250.186.99United States
AS15169GOOGLE
1216.58.206.68United States
AS15169GOOGLE
1142.250.185.163United States
AS15169GOOGLE
192.53.96.105Russia
AS9123Jsc timeweb
177.88.21.119Russia
AS13238YANDEX LLC
187.250.250.119Russia
AS13238YANDEX LLC
137.9.64.225Russia
AS13238YANDEX LLC
177.88.44.55Russia
AS13238YANDEX LLC
187.250.251.119Russia
AS13238YANDEX LLC
4324--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B273B5E741F0D0E14A4FC3B19D36569BDD7624BFDE85528479DC0A106F82EF98883AAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:jyfFVtrVSqBLoHj0PxiHm/ouVHzMd/ENRzGXLIN0:E3SqBLoHj0Au1MMMLIG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:77922:8EVAbuERCgFcJAAAQQAQohCEK6CEQAG1DA0rEGghEACfLgNMki4EATkIWcxFiAVHCeQAfAMAIGKDgOyAIxRwjAgIAoIYIUwT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00007e7e1e7e7e3e
Perceptual Hash:957c693a2ec3c293
Difference Hash:0332c0e0b8eccaea
Wavelet Hash:00007e7e1e7e3a7e
Color Hash:#3a5b78

Other Hashes

Crop Resistant:0332c0e0b8eccaea

Scan History

Scan history not available

Unable to load historical scan data