Security Scan Report: kamb-fenster.de

Site favicon
Submitted: Sep 23, 2026, 7:47:24 AMCompleted: Sep 23, 2026, 7:48:00 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 89%

9
Risk Score

Legitimate-looking Kamb window business whose site is compromised, injecting EtherHiding malware via a blockchain RPC endpoint and a resource flagged on 2 feeds, with a CRITICAL network-trojan IDS alert.

Risk Factors (5)
CRITICAL network trojan IDS signature (EtherHiding exfiltration)
Multi-source corroborated malware IoC on loaded resource xaz2.com
Blockchain RPC call consistent with EtherHiding malware retrieval
Primary domain itself reported as a malware loader
Very new (19-day-old) domain with no reputation
Domain age information unavailable

Details

Page Title

Fenster & Türen München. Kamb GmbH Ottobrunn

Scan Type

public

Domain Name Analysis

Within the German country-code top-level domain (.de), 'kamb-fenster.de' is registered and has no subdomain. The second-level label 'kamb-fenster' is 12 characters long with three vowels and eight consonants; bonus characters include 1 hyphen. Splitting it apart reveals four words: kam, b, fe, nster. Median word length comes out to 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kamb-fenster.de

Page Load Overview

1.76s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:6,600 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%
news/blog
40%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12185.30.32.182Germany
AS48324webgo GmbH
10104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10142.251.20.132Google · CDNUnited States
AS15169Google LLC
424--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15DE20971D1A041E93F0EA778E6E6B32CA1A4A616C912AF73B1FD304C46545FB00E795F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:g9i5Q62I/xE6x4g5bn/9/444wRrNL9sGcZdypa2Xz7ah+8+lEER:2iCVI9sGsypL7aO1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:34127:gErEoDmFkigPEh5uBIRJiABhQIAEm4tIIQTD07gJOEgwQBRUwSA18jJPESxROmRgKZAbAgQAJAO1yAVzCLRQWiA8wAAQ0REB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cdcfcf47195fe7fe
Perceptual Hash:b139f78c0cfe5901
Difference Hash:1599999db3bb4de8
Wavelet Hash:c1cd4505091fe77e
Color Hash:#78763a

Scan History

Scan history not available

Unable to load historical scan data