Security Scan Report: sns.grotominpgroup.pl

Submitted: Sep 13, 2026, 9:47:42 AMCompleted: Sep 13, 2026, 9:48:25 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 74%

8
Risk Score

Primary domain is a single-source Quasar RAT Indicator of Compromise match; combined with a 63-day-old domain, obfuscated JS, and a bare DDoS-challenge gate, this is high-risk malware infrastructure.

Risk Factors
Domain flagged as Quasar RAT (malware) infrastructure in threat intelligence
Recently registered domain (63 days) with no reputation
Obfuscated JavaScript with encoding/decoding routines on a bare challenge page
Circular redirect / JS-driven interstitial masking the real destination
ET HUNTING obfuscator-usage network alert
Domain age information unavailable

Details

Page Title

Just a moment please...secondary capture

Scan Type

public

Domain Name Analysis

Within the Polish country-code top-level domain (.pl), 'sns.grotominpgroup.pl' is registered with subdomain 'sns'. The registrable portion 'grotominpgroup' spans 14 characters containing five vowels alongside nine consonants. Tokenizing the label suggests 5 words: gro, tom, in, p, group. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sns.grotominpgroup.pl

Page Load Overview

4.87s
Total Load Time
151 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:96 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical64% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
64%
technology software
58%
cryptocurrency blockchain
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.250.154.95Google · CDNUnited States
AS15169Google LLC
1185.11.145.254Netherlands
AS47674Net Solutions - Consultoria Em Tecnologias De Informacao, Sociedade Unipessoal LDA
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1185.11.145.145Netherlands
AS47674Net Solutions - Consultoria Em Tecnologias De Informacao, Sociedade Unipessoal LDA
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
76--

Detected Technologies2

Bootstrapv3.3.4
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13EF020A35820580CB350D5586CE5F11CCDE9880FA6888CC4F9CE21AD1FD8BCFE4AB90C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hxzJ6QclfjgANH1cS52NUaZ/Jxs3ZELQUmJzNVG:hxzJsEApp8fk3wQPfVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:587:AAQAAAAAAAAAAAEBAAAAAYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAgAAAAAAEAAAAAAAAAAAACAAAAIAIA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000000018180000
Perceptual Hash:cc3333cccc3399cc
Difference Hash:0000000032300800
Wavelet Hash:3c3c3c3c38303030
Color Hash:#784a3a

Other Hashes

Crop Resistant:0000000032300800

Scan History

Scan history not available

Unable to load historical scan data