Security Scan Report: ch642005-wordpress-hq1aq.tw1.ru

Redirected to: https://vh456.timeweb.ru/blocked/?ref=ch642005-wordpress-hq1aq.tw1.ru#8283cb423420eab00

Site favicon
Submitted: Nov 22, 2025, 6:11:30 PMCompleted: Nov 22, 2025, 6:12:17 PMpubliccompleted
Loading additional data...

Summary

This website contacted 20 IPs in 3 countries across 11 domains to perform 52 HTTP transactions. The main domain is vh456.timeweb.ru.

Submitted URL: https://ch642005-wordpress-hq1aq.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#8283cb423420eab00

Effective URL: https://vh456.timeweb.ru/blocked/?ref=ch642005-wordpress-hq1aq.tw1.ru#8283cb423420eab00Redirected

The Cisco Umbrella rank of the primary domain is #163,229 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 70%

5
Risk Score

Site shows signs of compromise but lacks active phishing or malware; treat as suspicious.

Risk Factors
Compromised WordPress URL suggests possible site hijack
New or unknown domain age increases suspicion
Low ranking in Cisco Umbrella reputation database
Safety Factors
Final destination is a Timeweb block page, not a credential collection site
No forms collecting passwords, usernames, or payment information
No malicious Indicators of Compromise matches found
Domain age information unavailable

Details

Page Title

Домен заблокирован в Timeweb

Scan Type

public

Language

🇷🇺

Russian

(60% confidence)

Category

corporate business

(51%)

Domain Information

Domain 'ch642005-wordpress-hq1aq.tw1.ru' uses the Russian country-code top-level domain (.ru); it also runs on subdomain 'ch642005-wordpress-hq1aq'. Its registrable label 'tw1' stretches across 3 characters holding zero vowels versus 2 consonants, notching one digit. Tokenizing the label suggests two words: tw, 1. Expect 1.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ch642005-wordpress-hq1aq.tw1.ru/wp-content/plugins/SG2sms/sgfar/pages/index.php?lsg#8283cb423420eab00

Page Load Overview

1.05s
Total Load Time
52
HTTP Requests
11
Domains
1.3 MB
Total Size

Language Analysis

Primary Language

🇷🇺Russian
Code: ru
Confidence:60%
Script:Cyrillic
Direction:ltr

Detection Details

Language Code:ru
Detection Confidence:60%
Script Type:Cyrillic
HTML Lang Attribute:en
Text Length:1,736 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ru

Website Classification

Primary Category

corporate business51% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
51%
technology software
39%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1477.88.21.119Russia
AS13238YANDEX LLC
1492.53.96.141Russia
AS9123Jsc timeweb
1187.250.250.119Russia
AS13238YANDEX LLC
8142.250.185.99United States
AS15169GOOGLE
737.9.64.225Russia
AS13238YANDEX LLC
277.88.44.55Russia
AS13238YANDEX LLC
277.88.55.88Russia
AS13238YANDEX LLC
25.255.255.77Russia
AS13238YANDEX LLC
287.250.251.119Russia
AS13238YANDEX LLC
22a03:6f00:1::5c35:608dSt Petersburg, St.-Petersburg, Russia
AS9123Jsc timeweb
5220--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12863C7E701F0D0E14A4FC3B19D365A9B9D7624BFDE81928479DC0A507F92DF58883AAC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:kHfGeFKP7VkGdqCHG0PxiHm/ouVHHMjEENRzigLIN0:kHf5GBkGdqCHG0AupMVbLIG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:72932:EIyQTQMyDzAkREASIRADAkgSghECFDJAIIypujOgUFAmJJ1FAExIKBEgQEhynKiIyqBQEMfSAiAMAZ4AZj5ECGkBDwIgRgSQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:818181ffffffffff
Perceptual Hash:ba3b3ac0c5c5c5c5
Difference Hash:2b2b0b36f0c0b8e8
Wavelet Hash:000080807f7f7f7f
Color Hash:#8b79d2

Scan History

Scan history not available

Unable to load historical scan data