Security Scan Report: postafacile.online

Submitted: Sep 12, 2026, 8:47:31 PMCompleted: Sep 12, 2026, 8:49:49 PMpubliccompleted

Summary

This website contacted 7 IPs in 4 countries across 5 domains to perform 1 HTTP transaction. The main domain is postafacile.online and was registered 1 week ago.

Submitted URL: https://postafacile.online

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate-looking Italian postal site whose traffic shows a CRITICAL EtherHiding malware-exfiltration signature and loads xaz2.com (iclickfix, multi-feed malware). Consistent with a compromised site serving a hidden blockchain-based loader.

Risk Factors
CRITICAL IDS malware signature (EtherHiding exfiltration) on page traffic
Ethereum RPC endpoint resolution/exfiltration indicators (0xrpc.io)
Malicious third-party script/resource xaz2.com (iclickfix, multi-feed) embedded in page
Threat-intel malware reputation match on the primary domain
Pattern matches compromised legitimate site serving hidden blockchain-based malware loader
Domain age information unavailable

Details

Page Title

Homepage - PostaFacile - Servizi Postali OnLine

Scan Type

public

Language

🇮🇹

Italian

(80% confidence)

Category

government public service

(71%)

Domain Information

Within the modern generic top-level domain (.online), 'postafacile.online' is registered and has no subdomain. The second-level label 'postafacile' is 11 characters long split between 5 vowels and six consonants. Word splitting yields 3 words: post, a, facile. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://postafacile.online

Page Load Overview

90.47s
Total Load Time
97
HTTP Requests
5
Domains
315 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:it-IT
Text Length:5,110 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service71% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
71%
technology software
53%
blog personal website
48%
adult content
46%
news media journalism
45%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1951.83.99.234France
AS16276OVH SAS
13151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
13146.190.237.92Amsterdam, North Holland, Netherlands
AS14061DigitalOcean, LLC
13188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
13188.166.63.236Amsterdam, North Holland, Netherlands
AS14061DigitalOcean, LLC
13146.19.24.104Poland
AS201814MEVSPACE sp. z o.o.
13151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
977--

Page Statistics

97
Requests
5
Unique Domains
667.1 KB
Total Size

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19332F871839669D46E6CEA01BBF7A96C0646AC3B1433BDD7C10F2D8D293A4DB9005DA3

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:XlXbDN6BMD+gkdJfVzf4sJ2HQn/xE6oAi5a8zlvg/dP/xB/nkWHHDZUZ/X:X9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfn2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11278:AlC0GMcA2A5CokUkSMWYJUgCMGIGDGIjaxOgIDLEDAeABQCQAIByBIALmN0EKbhgZiRkoo4oAwShaTGKhaCdBkSCaLCAMesQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fffffff1333f3f23
Perceptual Hash:81fcf20368dbf207
Difference Hash:3b3207e3f7c7d8de
Wavelet Hash:b9d3f73103333f00
Color Hash:#8453ac

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data