Security Scan Report: g3.rs

Site favicon
Submitted: Sep 15, 2026, 10:47:45 PMCompleted: Sep 15, 2026, 10:48:28 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

The host domain g3.rs is positively identified as Raspberry Robin malware infrastructure by two independent threat feeds and a CRITICAL ET MALWARE IDS signature; the insurance-blog facade does not mitigate this domain-level threat.

Risk Factors
Primary domain flagged in threat intelligence as Raspberry Robin (rasprobin) malware infrastructure
Critical IDS signature matching DNS queries to a Raspberry Robin trojan domain
Discrepancy between benign-looking insurance blog content and malware-family reputation of the host domain
Domain age information unavailable

Details

Page Title

G3 -

Scan Type

public

Domain Name Analysis

Within the Serbian country-code top-level domain (.rs), 'g3.rs' is registered while skipping any subdomain. The second-level label 'g3' is 2 characters long holding zero vowels versus 1 consonant, along with 1 digit. Breaking it apart gives 2 words: g, 3. Average segment length settles at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://g3.rs

Page Load Overview

5.89s
Total Load Time
520 KB
Total Size

Language Analysis

Primary Language

🇭🇷HR
Code: hr
Confidence:49%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:sr-RS
Text Length:1,946 chars
Detector Agreement:100%
Language mismatch: Declared as sr-RS but detected as hr

Website Classification

Primary Category

healthcare medical100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
100%
travel tourism
95%
government public service
87%
finance banking
85%
documentation technical
67%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
152--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B5D24471E0E411763E6F877D82D1F328A5A8F600DA066BEA70F571648AC4BF714B7A0D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:054ZZdypa853J00z17Kg/TU4jUT7n4Ffthp:Iuyp7J02hp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28566:UgpMoBBBIIS4EEJhkYApqhGwRKY2IBFVgNGpBQAkAQBLkwhZBwAANXALGFDMEGEigVA2KEwBrGQUmFJBgsCQczHEwyEhU1Qn

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffdf8f8787c7ff
Perceptual Hash:b8cdc732c98c3cc3
Difference Hash:702a3a3a3c2c2c18
Wavelet Hash:ff828a8387878787
Color Hash:#4055bf

Scan History

Scan history not available

Unable to load historical scan data