Security Scan Report: ficofacil.com

Site favicon
Submitted: Oct 1, 2026, 8:45:25 AMCompleted: Oct 1, 2026, 8:46:08 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Well-aged domain but flagged as a malware loader on the primary domain and shows a CRITICAL ET MALWARE EtherHiding exfiltration alert plus blockchain RPC traffic — treat as compromised/malicious despite having no forms.

Risk Factors (5)
Malware-typed Indicators of Compromise match on the primary domain (unknown loader)
CRITICAL IDS alert ET MALWARE EtherHiding Exfil M2 (blockchain-based malware exfiltration)
Blockchain RPC domain (gateway.tenderly.co) contacted via DNS and TLS SNI, characteristic of EtherHiding infrastructure
Unranked domain (not in Cisco Umbrella top 1M) claiming/using the Ficohsa brand name in its title
Third-party script loaded from low-reputation domain zvh3.com
Domain age information unavailable

Details

Page Title

Ficohsa

Scan Type

public

Domain Name Analysis

The domain name 'ficofacil.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Its registrable label 'ficofacil' stretches across 9 characters split between four vowels and five consonants. It segments into three words: fico, fac, il. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ficofacil.com/

Page Load Overview

2.36s
Total Load Time
361 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:105 chars
Detector Agreement:50%

Website Classification

Primary Category

documentation technical33% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
33%
finance banking
32%
healthcare medical
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6172.67.207.51Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.217.208.95Google · CDNUnited States
AS15169Google LLC
2104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.94Google · CDNUnited States
AS15169Google LLC
2104.21.61.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
235.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2611--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T147E21932A1DA44C33F2DD7A5F1B1B22C9659A4228806DBB7B1FC355C5B949F700A3A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:I6cFAmgOLEzYmYOb0lZdapzHj/s0BTkgaPy:I6W18Waprj/NTkga6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33295:IVAJCgGmAIGAJKhbBCgQIICAgJgEe5SdARCAluEhjEYgEkURBijYoWAAEFGTPmpZ4wB8LwYXACCgslQCTAMCAZlAJSiQMEBA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffffff00
Perceptual Hash:979f2d9f079a028a
Difference Hash:70066068e86002c6
Wavelet Hash:fffe3c3c3e3c0000
Color Hash:#77862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data