Security Scan Report: ibericahost.eu

Site favicon
Submitted: Sep 17, 2026, 9:47:28 PMCompleted: Sep 17, 2026, 9:47:51 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

3-day-old domain whose page loads a resource from a malicious domain and triggers CRITICAL exploit-kit and EtherHiding malware-exfil IDS alerts with on-chain RPC C2 activity — likely injected malware/TDS.

Risk Factors (7)
Domain registered 3 days ago (critical age)
Two CRITICAL IDS alerts for exploit kit / traffic-distribution (ErrTraffic) activity
CRITICAL IDS alert for EtherHiding malware exfiltration
External resource served from aleverifocation.beer, corroborated malicious by multiple feeds
On-page blockchain RPC endpoints consistent with on-chain C2/wallet-drainer infrastructure
Primary domain reported as a malware loader
Mixed/injected page content (stove pipes, tripods, sleep products) atypical of a real hosting brand
Domain age information unavailable

Details

Page Title

iberica host – Hosting for you

Scan Type

public

Domain Name Analysis

Domain 'ibericahost.eu' uses the .eu country-code top-level domain without a subdomain. Its registrable label 'ibericahost' stretches across 11 characters split between 5 vowels and six consonants. It segments into four words: i, be, rica, host. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ibericahost.eu

Page Load Overview

2.69s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇳🇱Dutch
Code: nl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:nl-NL
Text Length:27,233 chars
Detector Agreement:67%

Website Classification

Primary Category

documentation technical56% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
56%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
85.200.6.112Rotterdam, South Holland, Netherlands
AS49544i3D.net B.V
2172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.157.119Google · CDNUnited States
AS15169Google LLC
2104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
235.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2142.251.156.119Google · CDNUnited States
AS15169Google LLC
2178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
2142.251.110.94Google · CDNUnited States
AS15169Google LLC
2142.251.154.119Google · CDNUnited States
AS15169Google LLC
3213--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EA53539297B058F8797F87BB4A04A1144573E6128D0D3BD9B0F2E293F59CE7506E3B0A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ai8qEu6u8IdcmRiBmgT0cTrnbO27k3eypwYMIu32N:GIdcmRiBmgT0cTrnbO27k33t

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:61925:WqghmNbSDAhpREASAIUCRQGQADEZEBmDwqMlpgEznIyUgYBAEAaIgIKAQwAOEAcbGgFCIBAgUIYYUxTpp1kY0siQnYjKBQNE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffff01010001
Perceptual Hash:bfd0d52be5c0342a
Difference Hash:2222300255554157
Wavelet Hash:ffffdfff00010000
Color Hash:#87c58f

Other Hashes

Crop Resistant:2222300255554157

Scan History

Scan history not available

Unable to load historical scan data