ch136645.tw1.ru favicon

ch136645.tw1.ru

Category: Phishing

Scanned: Aug 24, 2026, 17:17 UTC · First seen: Aug 24, 2026 · Threat Engines: 19 / 91 · Times Scanned: 1
5 / 100 Trust Score Based on scan findings at the time of analysis
Potentially Dangerous
0 - High Risk50 - Moderate100 - No Threats
Fresh scan recommended
Last scanned 14 days ago - security status may have changed since then.
Not scanned has not been scanned yet. Hit Scan Now to check it.

Scans can take up to 5 minutes to complete. Please keep this tab open - we'll redirect you to the report when it's ready.

Failed
Scan unavailable
Scan failed
Protect yourself from potentially harmful websites
Combo Cleaner's real-time web protection module actively blocks access to scam, phishing & malware-infected websites.
★★★★★ 4.8 / 5 Recommended by PCrisk.com editors Windows · Mac · Android · iOS
Download Combo Cleaner Free scan · no signup

To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Get PCrisk security checks in your Google results Add PCrisk as a preferred source and our scan reports and malware guides are prioritised for you in Google.
Add PCrisk as preferred source
Screenshot of ch136645.tw1.ru Captured Aug 24, 2026
https://ch136645.tw1.ru
Screenshot of ch136645.tw1.ru
This website has been flagged as potentially harmful
Screenshot blurred for safety. Multiple security engines flagged potential threats at the time of scanning.
20 years (tw1.ru)
Not Ranked - This website does not appear in the Tranco top list
Flagged by 19 of 91 engines
✓ Valid (TLS)
JSC "TIMEWEB"
St Petersburg, Russia
nginx/1.30.4
Unknown
92.53.96.169
Domain & WHOIS Information
Registrar Unknown
Registered June 29, 2006 (tw1.ru)
Expires July 31, 2027
Name Servers ns1.timeweb.ru.
DNSSEC Unknown
Hosting JSC "TIMEWEB"
This is a subdomain of tw1.ru. The WHOIS data above belongs to the parent domain, not to ch136645.tw1.ru. The actual creation date of this subdomain is unknown and could be much more recent than the parent.
Reputation & Threat Check 91 security engines checked
19
19 of 91 engines flagged this website Flagged by 19 security vendors at the time of scanning
Not flagged Flagged
Flagged by 19 of 91 engines
Direct Threat Database Sources
View detailed engine results on VirusTotal
File Scan Summary Powered by Quttera Engine
4 files scanned
No threats
4
Low Risk
0
Medium Risk
0
High Risk
0
No threats Low Risk Medium Risk High Risk
ch136645.tw1.ru/# 11.3 KB No threats
ch136645.tw1.ru/files/logo.svg 1.8 KB No threats
ch136645.tw1.ru/files/style.css 186.2 KB No threats
ch136645.tw1.ru/static/min/?f=css/reset.css%2Ccss/design-system.css%2Cfonts/font-barlow.css%2Cfonts/font-montserrat.css&1749552812 196 B No threats
External Links & Domains
4
External Links
3 Flagged
0
Iframes
Clean
2
Referenced Domains
1 Flagged
4
Flagged Resources
Detected
ch136645.tw1.ruFlagged: Generic Suspicious Object
http://ch136645.tw1.ru/./files/logo.svgFlagged: Generic Suspicious Object
http://ch136645.tw1.ru/./files/style.cssFlagged: Generic Suspicious Object
http://ch136645.tw1.ru/static/min/?f%3Dcss/reset.css,css/design-system.css,fonts/font-barlow.css,fonts/font-montserrat.css&1749552812Flagged: Generic Suspicious Object
http://ch136645.tw1.ru/./files/logo.svgFlagged: Generic Suspicious Object
http://ch136645.tw1.ru/./files/style.cssFlagged: Generic Suspicious Object
http://ch136645.tw1.ru/static/min/?f%3Dcss/reset.css,css/design-system.css,fonts/font-barlow.css,fonts/font-montserrat.css&1749552812Flagged: Generic Suspicious Object
https://ar24-courier.compte-clients.com/icon.pngNot flagged
ch136645.tw1.ruFlagged: Generic Suspicious Object
ar24-courier.compte-clients.comNot flagged
ch136645.tw1.ru Overview

Description of ch136645.tw1.ru

This domain appears to host a French-language login page branded as "AR24," with messaging about confidentiality, data protection, and access to an electronic registered letter or attached documents. The page title and screenshot suggest it is presenting itself as a document-delivery or secure correspondence portal rather than a general informational website.

The domain name itself, ch136645.tw1.ru, does not appear to match the AR24 branding shown on the page. The page also references an external image from a separate domain containing "courier" and "compte-clients," which may indicate an attempt to imitate a customer-access portal for delivery or registered-mail services. Based on the available categories and page content, the site appears to be associated with credential collection under the guise of a legal or professional communications service.

Although the domain is old, the visible content does not resemble a primary corporate website and instead appears to be a narrowly focused sign-in page. That pattern is commonly seen on temporary campaign pages or cloned login portals.

Safety Assessment for ch136645.tw1.ru

Multiple independent security signals raise concern about this domain at the time of this scan. It was flagged by 19 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, one threat database listing was present, and the page screenshot shows a branded login-style interface asking users to continue in order to access a message or attachment, which is a pattern often associated with credential-harvesting pages.

There are also contextual warning signs beyond the engine detections. The domain name does not appear to align with the AR24 branding displayed on the page, which may indicate the site is impersonating or mimicking another service. The domain's IP address is also listed on one mail-reputation blocklist; this is a weaker signal than direct phishing detections, but it still adds some caution. While one malware scan reported no directly flagged files and only generic suspicious-object heuristics, that cleaner result is outweighed here by the broader multi-engine phishing consensus and the page's login-lure presentation.

Based on these findings, this website may pose potential risks to visitors.

Technical Description

The site was reachable over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, expiring in March 2027. It is hosted on IP address 92.53.96.169, served by nginx/1.30.4, and appears to be hosted by JSC "TIMEWEB" in St Petersburg, Russia. The domain uses nameservers associated with the same hosting provider.

The domain itself is relatively old, having been created in 2006, which can sometimes lend legitimacy, but age alone does not offset phishing indicators when a subdomain or hosted page appears to be abused. DNSSEC status was reported as unknown. No iframe activity was observed in the supplied scan data, but several internal resource URLs were marked with generic suspicious heuristics.

HTTP Redirect Chain
No redirects detected - direct connection to destination
Website Insights
Not Ranked
Tranco Rank
Not in Top 1M
Visitors Unknown
Category: Phishing
Rank History (30 days)
No rank data available
No cookies data available
Dispute This Score For website owners
Believe this score is inaccurate?
If you are the website owner and believe the scan results contain errors or false positives, you can submit a dispute for manual review. Our team typically responds within 1-2 business days.
You will be asked to verify your email before the dispute can be processed.
By submitting this form, you confirm that the information provided is accurate. Disputes are reviewed manually and results may take up to 48 hours to update.
One more step…
To submit your dispute for ch136645.tw1.ru, please click the verification link we just emailed you. Once verified, we'll review it within 1-2 business days.
This report was generated automatically and is provided for informational purposes only. Results are based on a point-in-time scan and may contain false positives or incomplete data. This does not constitute a security audit or certification. No vendor in the market can guarantee a 100% detection rate. If you believe this report is inaccurate, please submit a dispute.

Share your experience with this website. Was it safe? Did you encounter any issues?