Security Scan Report: necgroupbd.com

Submitted: Sep 18, 2026, 3:47:28 PMCompleted: Sep 18, 2026, 3:48:00 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Established NEC Group site appears compromised: primary domain and loaded xaz2.com are flagged for malware, and a critical IDS alert shows EtherHiding exfiltration. Avoid interaction; investigate server compromise.

Risk Factors (4)
Primary domain flagged as RAT malware in threat intelligence
Loaded third-party resource xaz2.com flagged as iclickfix malware by multi-source intelligence
Critical network IDS alert for EtherHiding exfiltration
External Ethereum Sepolia RPC domain present, consistent with EtherHiding C2/exfiltration
Domain age information unavailable

Details

Page Title

NEC GROUP – Always there for you

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'necgroupbd.com' is registered with no subdomain. The second-level label 'necgroupbd' is 10 characters long containing three vowels alongside seven consonants. Breaking it apart gives three words: nec, group, bd. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://necgroupbd.com

Page Load Overview

12.58s
Total Load Time
593 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,215 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business77% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
77%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2266.29.151.83United States
AS22612Namecheap, Inc.
21104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
643--

Detected Technologies6

WordPressv7.0.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BAC20B31D1A51185BF1ED7A9F2E2722CA644A926C512B7F770BE205C457C8FB00A7D2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:I9i5Q62I/xE6x4g5bn/HeZdypGoQzEH9R:OiC4eypzQzEH9R

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26961:CAmIxEEIRKKohWAMmQgAkpCqIRE4ilCg9ULggAUoddAgIURCQFSolBIYUXoG7ULEkFQUmcNIXAAWEImDEIhEwALQIOAZKiEh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000ffffffff3c3ff
Perceptual Hash:a51b3f2f036cc3e0
Difference Hash:787a00a080262606
Wavelet Hash:000efe7e7e9280f6
Color Hash:#931f5f

Other Hashes

Crop Resistant:787a00a080262606

Scan History

Scan history not available

Unable to load historical scan data