Security Scan Report: theficobooster.com

Submitted: Oct 3, 2026, 4:25:23 AMCompleted: Oct 3, 2026, 4:26:10 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Compromised site serving the Macfinger ClickFix/AMOS stealer and ErrTraffic injector, with a fake Cloudflare verification overlay; critical YARA, kit-roster and IDS hits. Do not visit or run the shown commands.

Risk Factors (5)
Known malicious ClickFix/AMOS stealer kit injected into the page
Fake Cloudflare 'Human Verification' overlay instructing Windows users to open Terminal and paste commands
EtherHiding exfiltration traffic to blockchain-based dead-drop infrastructure
Injected SEO spam content unrelated to the site's stated credit-repair purpose (indicates site compromise)
Primary domain reported in threat intelligence as malware (clearfake)
Domain age information unavailable

Details

Page Title

The FICO Booster – Boost Your Credit Score the Right Way.

Scan Type

public

Domain Name Analysis

The domain 'theficobooster.com' uses the commercial generic top-level domain (.com). The second-level label 'theficobooster' is 14 characters long with 6 vowels and eight consonants. Splitting it apart reveals three words: the, fico, booster. Median word length comes out to 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://theficobooster.com/

Page Load Overview

12.56s
Total Load Time
906 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:7,017 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism97% confidence
Type: spa
Method: ml+structural

All Detected Categories

news media journalism
97%
entertainment media
95%
government public service
90%
blog personal website
86%
finance banking
84%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5160.153.0.30Cloudflare · CDNUnited States
AS209242Cloudflare London, LLC
4142.251.110.95Google · CDNUnited States
AS15169Google LLC
477.221.153.211Paris, Île-de-France, France
AS210644Aeza Group LLC
423.207.210.148Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
4142.251.14.94Google · CDNUnited States
AS15169Google LLC
435.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
4104.20.46.180Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8120--

Detected Technologies12

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11DB3E935E5F5302732EF43B8419263099D686543DBD60B99F1FCD1902F8AEAA6C6370E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:SfAypFFuc6VAngQbgt/Wo1wo0MKrVYTiqRe/0SE:SfBfFuFQi/Wo1wo0MKrVYTiqC0SE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:107926:jA08UtNJ00KYWJYlAJyAkyYRYEFgGt8whK5BKDhBAIWFQCVCQJIQiQMjQggTUxBehVAQHGoUwBEDWCA+gbaHALEsGxApFQNY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefeffe7e7ffffff
Perceptual Hash:aa55555577aa88aa
Difference Hash:0000010909010101
Wavelet Hash:323233232d3d0f0f
Color Hash:#2dd298

Other Hashes

Crop Resistant:0000010909010101

Scan History

Scan history not available

Unable to load historical scan data