Security Scan Report: travelindiadifferently.fr

Site favicon
Submitted: Sep 13, 2026, 2:47:30 PMCompleted: Sep 13, 2026, 2:49:36 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 84%

8
Risk Score

Legitimate-looking but compromised travel site: page loads exploitable third-party domains, blockchain RPC C2 and workers.dev payloads, triggering 5 CRITICAL EtherHiding malware-exfiltration IDS alerts.

Risk Factors (5)
CRITICAL IDS signatures for EtherHiding malware exfiltration (x5)
Corroborated malicious third-party exploitation-kit domain (3 feeds)
Corroborated malicious IP:port serving an exploitation kit (2 feeds)
Primary domain itself tagged as a malware loader
EtherHiding blockchain RPC infrastructure observed in DNS/TLS traffic
Domain age information unavailable

Details

Page Title

Maison - TID

Scan Type

public

Domain Name Analysis

The domain 'travelindiadifferently.fr' uses the French country-code top-level domain (.fr). The registrable portion 'travelindiadifferently' spans 22 characters containing eight vowels alongside 14 consonants. Tokenizing the label suggests 3 words: travel, india, differently. Average segment length settles at six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://travelindiadifferently.fr

Page Load Overview

85.45s
Total Load Time
14.1 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr-FR
Text Length:7,515 chars
Detector Agreement:67%

Website Classification

Primary Category

travel tourism98% confidence
Type: spa
Method: ml+structural

All Detected Categories

travel tourism
98%
education learning
60%
corporate
35%
adult content
27%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15142.251.110.95Google · CDNUnited States
AS15169Google LLC
6146.75.121.21Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
6151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
6162.241.253.243Phoenix, Arizona, United States
AS31898Oracle Corporation
6104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.251.127.97Google · CDNUnited States
AS15169Google LLC
6104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.251.151.119Google · CDNUnited States
AS15169Google LLC
6142.251.20.95Google · CDNUnited States
AS15169Google LLC
14122--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CFC26472B08901273B0F9BBDD1A2732DFA9DE61ACD0667BAB0F4705C5590AF700A751E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:iAJEwL23y6Owf2Q4r0ZdSZUaAWkKpPQhFFekx9N:VxhgZdypHpPUx9N

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:27098:I6KECBECFpiXnDOgQOgxKmChkIoxOQGBQJkDUDctoIEqikBQGJBihhLigBEIUhICQAUEUQ8QokTMGRECBSwSL6lHQIHQYVTA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000038001000ffff
Perceptual Hash:8c53f34c6c336ccc
Difference Hash:8ac5d5133535490c
Wavelet Hash:003d3d013901ffff
Color Hash:#2dd277

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data