THUGS(red) DarkWeb/Monitor_

URL Scan

Alive Search Engine

Open

capture
Blocked: a challenge page was served instead of the siteCHALLENGE PAGE

The only capture we hold is a challenge page, not the service. It is kept for evidence but is not shown here as if it were the site. View the raw capture.

what the page says

URL and website scanner - urlscan.io

Website scanner for suspicious and malicious URLs

urlscan.io Home Search Live API Blog Docs Pricing Login urlscan.io A sandbox for the web URL Triage Public Scan Options Recent scans Updates every 10s - Last update: 19:57:45 URL Age Size IPs whm.www.www.admin.www.api.as.152-53-37-155.plesk.page/ 11 seconds 2 MB 119 32 6 bielefeldspielbank.com.de/ 12 seconds 651 KB 34 1 1 personaltrainer-ingo-gaube.de/ 14 seconds 4 MB 20 3 2 astaging.xwold.rqpsnotexistsihgfed495639f7-a0b4-4c61-ba1b-8056f83ce0cf.mutgicon... 14 seconds 57 KB 3 1 1 masoswiss.com/ 16 seconds 1010 KB 77 9 4 www.festumvretensis.com.vuxenpedagogik.com/ 18 seconds 2 MB 12 2 1…

Page author: urlscan.io

reachability history
The 5 most recent checks.
When Status HTTP Response Bytes Via
4m ago Alive content moved 200 30 ms 44,865 chrome-stealth
1h ago Alive content moved 200 27 ms 44,865 chrome-stealth
2h ago Alive content moved 200 30 ms 44,865 chrome-stealth
4h ago Alive content moved 200 28 ms 44,865 chrome-stealth
6h ago Alive 200 31 ms 44,865 chrome-stealth
security headers
Csp
Raw
default-src 'self' data: urlscan.io sentry.urlscan.io; script-src 'self' data: developers.google.com www.google.com www.gstatic.com urlscan.io sentry.urlscan.io; style-src 'self' fonts.googleapis.com www.google.com cdnjs.cloudflare.com urlscan.io; img-src * data:; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com urlscan.io; child-src 'self'; frame-src https://www.google.com/recaptcha/; form-action 'self'; connect-src 'self' api.checklyhq.com sentry.urlscan.io urlscan.io *.urlscan.io https://www.google.com/recaptcha/; upgrade-insecure-requests; frame-ancestors 'none';
Directives
Default src
'self'data:urlscan.iosentry.urlscan.io
Script src
'self'data:developers.google.comwww.google.comwww.gstatic.comurlscan.iosentry.urlscan.io
Style src
'self'fonts.googleapis.comwww.google.comcdnjs.cloudflare.comurlscan.io
Img src
*data:
Font src
'self'fonts.gstatic.comcdnjs.cloudflare.comurlscan.io
Child src
'self'
Frame src
https://www.google.com/recaptcha/
Form action
'self'
Connect src
'self'api.checklyhq.comsentry.urlscan.iourlscan.io*.urlscan.iohttps://www.google.com/recaptcha/
Frame ancestors
'none'
Unsafe inline
no
Unsafe eval
no
Hsts
Max age
63072000
Include subdomains
yes
Preload
yes
X frame options
DENY
X content type options
nosniff
Referrer policy
same-origin
Cross origin
X xss protection
0
Cookies
Count
0
Secure
0
Httponly
0
Samesite
0
Score
80
Missing
permissions_policycoopcoepcorp
tls certificate
Protocol
TLS 1.3
Cipher
AES_128_GCM
Key exchange group
X25519MLKEM768
Signature algorithm
1027
Subject
urlscan.io
Issuer
YE2
San
*.urlscan.com*.urlscan.io*.urlscan.neturlscan.comurlscan.io
San count
5
Wildcard
yes
Valid from
2026-07-06 05:50:13
Valid to
2026-10-04 05:50:12
Days remaining
43
Self signed
no
Ct compliance
unknown
Ech
no
technology detected
Server
Raw
nginx
Name
nginx
Family
nginx
Js
  • Name
    reCAPTCHA
  • Name
    Bootstrap
Protocol
h2
what blocks us
Detected
yes
Kind
recaptcha
Vendor
Google
Label
Google reCAPTCHA
Confidence
100
Signals
reCAPTCHA api originreCAPTCHA static origing-recaptcha containergrecaptcha global
Self clearing
no
Waited ms
0
Http code
200
Via
chrome-stealth
contacts published
  • Total0
crypto addresses
  • Total0
forms on the page
Count
1
Kinds
Search
1
Has login
no
Has search
yes
Has upload
no
Forms
  • Kind
    search
    Method
    post
    Action
    https://urlscan.io/result/scan/
    Inputs
    3
    Types
    texttextareasubmit
    Password
    no
    File
    no
outbound onion links
  • onion_unique not tracked onion_unique
  • onion_total not tracked onion_total
  • clearnet_unique not tracked clearnet_unique 10
  • internal not tracked internal 26
  • external not tracked external 10
  • total not tracked total 42
  • truncated not tracked truncated
response headers
HeaderValue
cache-control public, max-age=60
content-encoding gzip
content-security-policy default-src 'self' data: urlscan.io sentry.urlscan.io; script-src 'self' data: developers.google.com www.google.com www.gstatic.com urlscan.io sentry.urlscan.io; style-src 'self' fonts.googleapis.com www.google.com cdnjs.cloudflare.com urlscan.io; img-src * data:; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com urlscan.io; child-src 'self'; frame-src https://www.google.com/recaptcha/; form-action 'self'; connect-src 'self' api.checklyhq.com sentry.urlscan.io urlscan.io *.urlscan.io https://www.google.com/recaptcha/; upgrade-insecure-requests; frame-ancestors 'none';
content-type text/html; charset=utf-8
date Fri, 21 Aug 2026 17:57:15 GMT
etag W/"af41-PtKeT94b+1Sk++lyCuVowh3IpJc"
referrer-policy same-origin
server nginx
strict-transport-security max-age=63072000; includeSubdomains; preload
vary Accept-Encoding
x-content-type-options nosniff
x-frame-options DENY
x-proxy-cache HIT
x-robots-tag all
x-xss-protection 0