Security Scan Report: arrebolcap.com

Site favicon
Submitted: Oct 3, 2026, 4:25:15 AMCompleted: Oct 3, 2026, 4:26:18 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Legitimate-looking Arrebol Capital site is compromised and serving an ErrTraffic/Exvicy ClickFix injection: a fake Cloudflare 'Human Verification' overlay that tricks Windows users into pasting a malicious Terminal command. Confirmed by two CRITICAL YARA kit matches and CRITICAL IDS malware alerts.

Risk Factors (5)
Known malicious ClickFix/ErrTraffic injection kit present in the page HTML (analyst-vetted roster match)
Fake Cloudflare 'Human Verification' overlay impersonating the Cloudflare brand to social-engineer users into running a Terminal command
Network IDS reports command-and-control/exfiltration traffic (EtherHiding Exfil) and ClickFix domain contact
Threat intelligence flags the primary domain as malware (clearfake) and several loaded third-party domains as malicious or attack-related
Blockchain RPC connections consistent with EtherHiding-style payload retrieval used by the injected loader
Domain age information unavailable

Details

Page Title

Arrebol Website : Arrebol Website

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'arrebolcap.com' is registered while skipping any subdomain. The core label 'arrebolcap' covers 10 characters holding 4 vowels versus 6 consonants. Splitting it apart reveals four words: ar, re, bol, cap. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://arrebolcap.com/

Page Load Overview

9.38s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,770 chars
Detector Agreement:60%

Website Classification

Primary Category

documentation technical86% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
86%
technology software
85%
cryptocurrency blockchain
83%
phishing scam
76%
government public service
75%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4162.215.248.204United States
AS46606Unified Layer
3104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3192.178.183.97Google · CDNUnited States
AS15169Google LLC
3132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3216.239.32.36Google · CDNUnited States
AS15169Google LLC
3172.67.130.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4013--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T186732B33F74864AA332F0284669A7768793D8839DF4B4EE671B62138D7815D33173A2D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:mftpGjW/nypK61KQ/8IiO7s4Myn4D46RM2I:mTy061KQ0gk46W2I

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:75200:KOt1YUaOAhBERZwMshhCJtYUZBEhQCAAwlGDQSEQCM7TBARA3ICXGBkGBjCSOEBdDIARBHpE51DWStKIHAUgiMs8GcSzhEiq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fcf8f8e1c3e7cf9f
Perceptual Hash:ea4a9ab32c92c73c
Difference Hash:c1090107870e1934
Wavelet Hash:38f8f0c0c1e38f8f
Color Hash:#931f67

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data