Security Scan Report: firstcallkuwait.com

Site favicon
Submitted: Oct 4, 2026, 3:19:05 AMCompleted: Oct 4, 2026, 3:20:19 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 94%

10
Risk Score

Legitimate-looking Kuwait electrician site whose WordPress pages carry appending ClickFix/ErrTraffic-Exvicy malware kits, malicious third-party scripts and EtherHiding IDS traffic. Compromised host serving malware — do not interact.

Risk Factors (5)
Analyst-vetted malicious kit roster hits (ClickFix FakeCAPTCHA, ErrTraffic/Exvicy WordPress injected loader, Win+X / macOS Terminal lures) present in the page body
Multiple CRITICAL high-precision YARA matches on the served HTML indicating a compromised WordPress site injecting a ClickFix malware loader
CRITICAL IDS alert for EtherHiding exfiltration and Spamhaus-listed traffic
Threat-intel reports of malware/IClickFix against the primary domain and scanned URL
Page loads scripts and beacons from several multi-source-flagged malicious third-party domains
Domain age information unavailable

Details

Page Title

Home - فيرست كول الكويت

Scan Type

public

Domain Name Analysis

The domain name 'firstcallkuwait.com' uses the commercial generic top-level domain (.com) without a subdomain. The registrable portion 'firstcallkuwait' spans 15 characters holding 5 vowels versus ten consonants. Breaking it apart gives 3 words: first, call, kuwait. Median word length comes out to five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://firstcallkuwait.com

Page Load Overview

14.47s
Total Load Time
4.3 MB
Total Size

Language Analysis

Primary Language

🇸🇦Arabic
Code: ar
Confidence:60%
Script:Arabic
Direction:rtl

Detection Details

HTML Lang Attribute:en-US
Text Length:5,116 chars
Detector Agreement:100%
Language mismatch: Declared as en-US but detected as ar

Website Classification

Primary Category

corporate business100% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
100%
government public service
100%
real estate property
99%
technology software
99%
documentation technical
99%

Detected Features

OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9198.251.89.200Luxembourg, Luxembourg, Luxembourg
AS53667FranTech Solutions
5104.26.9.123Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.20.95Google · CDNUnited States
AS15169Google LLC
5142.251.20.97Google · CDNUnited States
AS15169Google LLC
5142.251.14.156Google · CDNUnited States
AS15169Google LLC
535.208.237.19Google · CDNCouncil Bluffs, Iowa, United States
AS15169Google LLC
5104.21.3.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5216.239.32.36Google · CDNUnited States
AS15169Google LLC
5142.251.157.119Google · CDNUnited States
AS15169Google LLC
5142.251.20.148Google · CDNUnited States
AS15169Google LLC
18436--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T138932CF1F72F14251626111CE95AB2787EEDA872CB839AF1FEB9412CC4CD59C11EA708

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:5Yyp6rcQlVSFFcfMUFeYBa/+27DHE3w7srzoFbnS2BeV:55HYBa/+2/QnoNnS2BI

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:90259:pHVQAJEAhATGJSdYlxABmT6NBKFg5UyBwHhKYQcIBACpowgC1BBjhAGADFpMZJcHBQIBUiLNPWBroAggCEgIjk9O+CYpADA9

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cfc7c3c3ffffffff
Perceptual Hash:b03193c7cecccccc
Difference Hash:1818163600000008
Wavelet Hash:3f0703030f0fff00
Color Hash:#8453ac

Other Hashes

Crop Resistant:1818163600000008

Scan History

Scan history not available

Unable to load historical scan data