Security Scan Report: seniorenzentrum-bn.de

Site favicon
Submitted: Sep 19, 2026, 8:47:26 AMCompleted: Sep 19, 2026, 8:47:52 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate German senior care home site appears compromised: a critical 'EtherHiding' malware C2 signature, blockchain smart-contract lookups and obfuscated JavaScript indicate a hidden malware loader hosted on the page.

Risk Factors (5)
CRITICAL malware IDS signature (EtherHiding Exfil) fired on page traffic
Blockchain smart-contract C2 retrieval pattern (Tenderly/Ankr RPC + getDomain())
Primary domain threat-intel match as a malware loader
Heavily obfuscated JavaScript with dynamic code generation on a simple brochure site
Unranked domain with a low legitimacy score, page content inconsistent with a plain care-home brochure
Domain age information unavailable

Details

Page Title

Seniorenzentrum Haus Mühlenbach |

Scan Type

public

Domain Name Analysis

The domain 'seniorenzentrum-bn.de' uses the German country-code top-level domain (.de) without a subdomain. The second-level label 'seniorenzentrum-bn' is 18 characters long split between 6 vowels and 11 consonants; bonus characters include one hyphen. Splitting it apart reveals 4 words: senior, en, zentrum, bn. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://seniorenzentrum-bn.de

Page Load Overview

7.77s
Total Load Time
1.6 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:3,327 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical46% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
46%
real estate property
25%
news/blog
20%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12109.237.138.49Germany
AS45012dogado GmbH
10152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
1035.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
10178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
424--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17243A68FAB7736F57207C315BDD1AB3492DCC113DA1509E6BC22E6588BC2363057A29E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:0b1cad0b6jaSZ3Js79XYLErcywltt1s5bnsEOMugUbwAc:2rfRlP2bsEO1wAc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:55874:RYAb4AiApHUM4kBKAwXD1BqA+M5CnQhBgSAEBoWEAEhMg4kAWGHBGAYk4uEAADmB6AXt4DAoUQsAN8BHAgrlHNSJYAIKwqEz

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:dbf1b09181ffffff
Perceptual Hash:ea6a91b13d6dc149
Difference Hash:33212121313c2f30
Wavelet Hash:d991800000dfffff
Color Hash:#40bf62

Scan History

Scan history not available

Unable to load historical scan data