Security Scan Report: www.bilisimzamani.net

Site favicon
Submitted: Oct 3, 2026, 10:25:11 AMCompleted: Oct 3, 2026, 10:25:54 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Compromised WordPress entertainment site. YARA-confirmed ErrTraffic/Exvicy loader plus a fake Cloudflare 'Human Verification' ClickFix overlay telling visitors to paste commands into Windows Terminal; 20 CRITICAL EtherHiding-exfil IDS alerts. Avoid.

Risk Factors (5)
Injected ErrTraffic/Exvicy WordPress loader with obfuscated Base64/XOR + new Function decoding (YARA-confirmed)
ClickFix fake 'Human Verification' overlay instructing users to run pasted commands in Windows Terminal/PowerShell
20 CRITICAL IDS alerts: ET MALWARE EtherHiding Exfil M2 (network trojan, EtherHiding C2 exfiltration)
Multi-source threat-intel match on the primary domain and its URL (clearfake / unknown malware)
Blockchain testnet RPC endpoints contacted by page scripts (wallet-drainer / EtherHiding infrastructure pattern)
Domain age information unavailable

Details

Page Title

Bilisimzamani – The Entertainment Arena

Scan Type

public

Domain Name Analysis

Domain 'www.bilisimzamani.net' uses the network infrastructure generic top-level domain (.net) with subdomain 'www'. The second-level label 'bilisimzamani' is 13 characters long containing 6 vowels alongside seven consonants. Tokenizing the label suggests 3 words: bilis, im, zamani. Expect 5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.bilisimzamani.net/

Page Load Overview

9.43s
Total Load Time
1.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:7,431 chars
Detector Agreement:75%

Website Classification

Primary Category

entertainment media99% confidence
Type: spa
Method: ml+structural

All Detected Categories

entertainment media
99%
news media journalism
70%
gambling betting
55%
government public service
38%
technology software
37%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15172.67.207.245Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.20.95Google · CDNUnited States
AS15169Google LLC
5150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
5172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.20.94Google · CDNUnited States
AS15169Google LLC
5178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
5104.21.58.216Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
515.197.152.159Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
53.33.196.84Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
535.71.129.99Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
9016--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15E9309F390A521364B1797D292CC6A189635A927CA034E95B3FD1108AFC5EF523E732F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:CMVM6MVM+MVMfMVMnMVMsMVMUMVMvsptIUjWOapN5aRHwtVcEezpk2tB0ms97r6R:Cr5aCtVcEb9/6LicxNEU9J

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:90721:AKUJkIMGsEm2KrLoAAUSoBhiQTIMSABwFcEDIjwhRQVOgIAEMAWogZCBRtQ4ZMEECLIEkkgSEANCAyAHD0CTbFBkwQGuBaix

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffff7e0000
Perceptual Hash:d3f777d4288808cd
Difference Hash:0e08100000827171
Wavelet Hash:ffe7ff31b1000000
Color Hash:#2dd298

Other Hashes

Crop Resistant:0e08100000827171

Scan History

Scan history not available

Unable to load historical scan data