Security Scan Report: tc-donauwoerth.de

Redirected to:
https://www.tc-donauwoerth.de/
Site favicon
Submitted: Sep 19, 2026, 6:47:28 PMCompleted: Sep 19, 2026, 6:48:09 PMpubliccompleted

This website contacted 9 IPs in 3 countries across 11 domains to perform 57 HTTP transactions. The main domain is tc-donauwoerth.de and was registered 3 weeks ago.

Submitted URL: https://tc-donauwoerth.de

Effective URL:

https://www.tc-donauwoerth.de/
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Genuine 1930 tennis club site that appears COMPROMISED — critical EtherHiding malware IDS alerts, blockchain RPC C2 endpoints, and stealer/malware threat-intel on the domain and a loaded resource. Avoid.

Risk Factors
CRITICAL IDS malware alert (EtherHiding exfiltration) on page network traffic
Page loads blockchain RPC endpoints (1rpc.io, 0xrpc.io) used for EtherHiding-style C2 resolution
Primary domain flagged as stealer malware in threat intelligence
Page loads a third-party resource (qaz0.com) confirmed as malware by two independent feeds
Domain age information unavailable

Details

Page Title

Tennisclub Donauwörth e.V.

Scan Type

public

Domain Name Analysis

Within the German country-code top-level domain (.de), 'tc-donauwoerth.de' is registered and has no subdomain. Its registrable label 'tc-donauwoerth' stretches across 14 characters split between 5 vowels and eight consonants, plus one hyphen. Segmentation suggests four words: tc, donau, woe, rth. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tc-donauwoerth.de

Page Load Overview

5.41s
Total Load Time
678 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de-DE
Text Length:2,795 chars
Detector Agreement:100%

Website Classification

Primary Category

news/blog40% confidence
Type: spa
Method: structural

All Detected Categories

news/blog
40%

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
981.169.145.143Germany
AS6724Strato GmbH
6185.111.111.158Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
6185.111.111.156Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
6188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6146.19.24.104Poland
AS201814MEVSPACE sp. z o.o.
6188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6185.111.111.157Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
6185.111.111.155Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
6159.69.24.179Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
579--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D4723A3342DE35C27E2CC925B7B5F25C4244A027A63B7E57E10A2AAC70597EF0895E4B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:/hliMULjSak0mqUeFXtHcaNqZh3TqzgmzHz8Cl8XVe96bJh8QlCjI66Z+mOxQtgm:JdUqQm0PIlGDzHz8CMe9ihpoI4mFWM

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17443:J7JbEEUAQBRgQUGigCkBIBgHJqGSEK+QCggLFYCCkJ4M0WyFojCpgBkCFUSgJYQQlwAiQwBpss52siCAEAAgwIqYJAFSCUD5

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000183d3d1d0101
Perceptual Hash:9a4b6336cf4b1c4c
Difference Hash:598db17131290d21
Wavelet Hash:00e718bdbd9f8383
Color Hash:#9153ac

Scan History

Scan history not available

Unable to load historical scan data