Security Scan Report: naturgeeks.com

Site favicon
Submitted: Sep 20, 2026, 9:47:30 PMCompleted: Sep 20, 2026, 9:48:21 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 76%

8
Risk Score

Established vitamin-bar shop appears compromised: primary-domain RAT/malware indicator, a CRITICAL EtherHiding exfiltrating IDS alert via a blockchain RPC, and a malware-flagged external resource. No phishing forms, but avoid interaction.

Risk Factors (4)
Indicators of Compromise on the primary domain naming a RAT/malware family
CRITICAL IDS alert for EtherHiding exfiltration over a blockchain RPC
Malware-flagged third-party script/domain (xaz2.com / iclickfix) loaded by the page
Anomalous outbound connections to blockchain RPC infrastructure from a non-Web3 retail site
Domain age information unavailable

Details

Page Title

Natur Geeks Protein and Vitamin Bars

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'naturgeeks.com' is registered and has no subdomain. The registrable portion 'naturgeeks' spans 10 characters containing 4 vowels alongside six consonants. Tokenizing the label suggests two words: natur, geeks. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://naturgeeks.com

Page Load Overview

12.50s
Total Load Time
3.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,218 chars
Detector Agreement:80%

Website Classification

Primary Category

healthcare medical70% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
70%
documentation technical
51%
adult content
49%
corporate
35%
e-commerce shopping
35%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7151.101.2.159Fastly · CDNUnited States
AS54113Fastly, Inc.
7104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.17.207.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.20.97Google · CDNUnited States
AS15169Google LLC
7104.17.208.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.110.97Google · CDNUnited States
AS15169Google LLC
735.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
723.59.17.83Akamai · CDNHamburg, Free and Hanseatic City of Hamburg, Germany
AS16625Akamai Technologies, Inc.
7172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10515--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F2432A33D17408653BAEE3BCB587B6D87D1C9036E60967B278B9356C45C86EB10A370E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:p/9i5Q62I/xE6x4g5bn/NO2MEc9nzgCUILZdypIT8swiu5CPT:ziCz2MEcVzgCUwypi8swiu5wT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:60081:2SihJxgDcAJGElGQj4RVLFCEooWQIKgIQwAQKtqAAYU2UAAkGo6gEcCNVEkjERIclQksCYpSQPN0SmuJCtAEDCTuIA0B51is

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:007fffffffff0000
Perceptual Hash:83891af7787ca532
Difference Hash:1de0d6968c487cad
Wavelet Hash:007f427fffff0000
Color Hash:#3a5678

Scan History

Scan history not available

Unable to load historical scan data