Security Scan Report: dosya.co

Submitted: Apr 15, 2026, 3:05:25 PMCompleted: Apr 15, 2026, 3:06:55 PMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 2 countries across 10 domains to perform 25 HTTP transactions. The main domain is dosya.co and was registered NaN years ago.

Submitted URL: https://dosya.co/8240nfesfd5p/mods.rar.html

AI Security Verdict

Low Risk

Confidence: 78%

2
Risk Score

The site appears low‑risk: old domain, no credential collection, no malware indicators, though it is unranked and has heavily obfuscated JavaScript.

Risk Factors
Domain is unranked in Cisco Umbrella top 1M (weak reputation signal)
High JavaScript obfuscation score (moderate signal without malware)
Safety Factors
Old, well‑established domain
Self‑branding matches domain (no impersonation)
No forms collecting sensitive data
No network IDS alerts
No malicious external IoC links
Domain age information unavailable

Details

Page Title

İndir mods rar

Scan Type

public

Language

🇹🇷

Turkish

(53% confidence)

Category

download file sharing

(93%)

Domain Information

Domain 'dosya.co' uses the Colombian country-code top-level domain (.co). Its registrable label 'dosya' stretches across 5 characters holding 2 vowels versus three consonants. Segmentation suggests two words: dos, ya. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dosya.co/8240nfesfd5p/mods.rar.html

Page Load Overview

1.54s
Total Load Time
28
HTTP Requests
14
Domains
476 KB
Total Size

Language Analysis

Primary Language

🇹🇷Turkish
Code: tr
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Language Code:tr
Detection Confidence:53%
Script Type:Latin
Text Length:810 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing93% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

download file sharing
93%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10142.251.110.94United States
AS15169Google LLC
2157.240.0.6Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
2104.18.11.207United States
2142.251.13.97United States
AS15169Google LLC
223.109.253.53Unknown
2195.201.111.49Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
2142.251.20.102United States
AS15169Google LLC
2104.16.174.226United States
AS13335Cloudflare, Inc.
2104.17.24.14UnknownUnknown
2142.251.20.95United States
AS15169Google LLC
2810--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FA12A556BDD6DC2B116241F4F7B3EA0EA8624153D702ED84B1EC02B6BFC1FA24C23649

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:KvHQue2/g+RtsBftXDm3A/SaHSTMdA+twFlQYOjXbPiqlc2Dbc:KvHQueSg+PsBftTUYMM+kvPlc2Dbc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:9658:MAFoJvoVCoQANqiVSBJzwUQAltqAMiBDoNERwUw3IImGmIEiKyARhwRIqegFJQASDHmmioFxRmIikk7kC1QIAClDE4ImxooI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff0000ffffff
Perceptual Hash:a72389890d27a7b7
Difference Hash:cc0c082c30000000
Wavelet Hash:00e7e70000fff3f3
Color Hash:#9ac587

Scan History

Scan history not available

Unable to load historical scan data