Security Scan Report: stankoff.ru

Redirected to:
https://www.stankoff.ru/
Site favicon
Submitted: Sep 20, 2026, 5:39:34 PMCompleted: Sep 20, 2026, 5:39:54 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 65%

5
Risk Score

A long-established domain is serving injected 'KillBot' booter content that beacons via obfuscated JS to abuse-flagged kill-bot.ru hosts — likely a compromise, not the site's real content. Avoid interaction.

Risk Factors
Compromised/piggybacked infrastructure: KillBot content on an unrelated legitimate domain
Encoded inline JavaScript posting data to an external abuse-flagged host
KillBot is a known DDoS-for-hire/booter service present in page content and network requests
Safety Factors
Domain stankoff.ru is well-established (28 years old)
No credential, password, or payment forms present
No YARA malware or Safe Browsing hits
Established domain (10223 days old) with no strong malicious indicators — risk clamped from 7 to 5
Domain age information unavailable

Details

Page Title

User verification...

Scan Type

public

Domain Name Analysis

The domain 'stankoff.ru' uses the Russian country-code top-level domain (.ru). The core label 'stankoff' covers 8 characters with 2 vowels and six consonants. Word splitting yields two words: stank, off. Average segment length settles at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://stankoff.ru

Page Load Overview

0.96s
Total Load Time
130 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Text Length:295 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software62% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
62%
e-commerce shopping
62%
documentation technical
56%
news media journalism
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8194.67.100.247Russia
AS197695Domain names registrar REG.RU, Ltd
131.192.105.204Moscow, Moscow, Russia
AS50867Hostkey B.v.
146.29.114.75Russia
AS48347JSC Mediasoft ekspert
1212.41.11.153Moscow, Moscow, Russia
AS50340JSC Selectel
1212.108.82.180Netherlands
AS57043Hostkey B.v.
1194.233.71.78Singapore, Singapore
AS141995Contabo Asia Private Limited
187.250.250.119Yandex · CLOUDRussia
AS13238YANDEX LLC
1190.115.31.218United Arab Emirates
AS59692IQWeb FZ-LLC
187.250.251.119Yandex · CLOUDRussia
AS13238YANDEX LLC
169--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T180A3D99985B3243605373079EBBF754D36B180039106DB33BC6D8666EFD0A3646F6BA8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:BaqoSjlluT7fa9hR8h9MYHPzzAidXPXomJ:BpP0T7fa9vmJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:101958:g2E5YSCA4sEvoSCAPQQhEA2ASgGBYAAARlTh/IkADQu0ICaloCAAVpKgkUABxREYADqJG0RgiMZWssRABImD20YBALsoQiBT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffe7
Perceptual Hash:b38ccc3333cccc33
Difference Hash:0000000808000008
Wavelet Hash:0c0c1c04273f3f27
Color Hash:#1f8293

Other Hashes

Crop Resistant:0000000808000008

Scan History

Scan history not available

Unable to load historical scan data