Security Scan Report: maxfel.se

Submitted: Oct 1, 2026, 4:27:47 PMCompleted: Oct 1, 2026, 4:28:44 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Compromised site hosting the ClearFake EtherHiding Polygon loader and rival-kit cleanup overlay (two roster-anchored YARA hits). Malware-distribution risk regardless of the harmless-looking joke content.

Risk Factors (5)
ClearFake Polygon EtherHiding contract loader injected into the page (YARA, roster-anchored, CRITICAL)
ClearFake rival-kit cleanup/overlay blocking script injected (YARA, roster-anchored, HIGH)
Second-stage remote script load (/js/all.min.js?m=1) gated on Windows user-agent and crawler evasion
Hidden overlay that blocks navigation for up to 45 seconds to force user interaction (ClickFix pattern)
Site content is unrelated injected SEO-spam casino/betting link farm
Domain age information unavailable

Details

Page Title

Smakar din Pepsi Max konstigt? Maxfel.se hjälper dig! - Zero taste. Full irritation.

Scan Type

public

Domain Name Analysis

The domain name 'maxfel.se' uses the Swedish country-code top-level domain (.se) without a subdomain. Count 6 characters in 'maxfel' with two vowels and 4 consonants. Breaking it apart gives three words: max, f, el. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://maxfel.se/

Page Load Overview

2.52s
Total Load Time
324 KB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:sv-SE
Text Length:4,558 chars
Detector Agreement:50%

Website Classification

Primary Category

gambling betting99% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
99%
finance banking
97%
education learning
93%
entertainment media
91%
adult content
90%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
465.21.122.251Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
4142.251.127.97Google · CDNUnited States
AS15169Google LLC
4192.0.77.48San Francisco, California, United States
AS2635Automattic, Inc
4216.239.32.36Google · CDNUnited States
AS15169Google LLC
4142.251.14.97Google · CDNUnited States
AS15169Google LLC
4216.239.34.36Google · CDNUnited States
AS15169Google LLC
246--

Detected Technologies8

WordPressv7.1.2
100%
JQueryv3.7.1
100%
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14F334B72A37D086AAB7E47E99C7A730CF87A60319E81D56AF0FB740444989F102E375D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:l/yZWOVAw7xWXypGfA8q1niaIGlEr55Qq5fjgiaRs:0ZNVAw9WikfA8q1niaIGlu5Qq5fy+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:52563:KLAUMFkjRfQkAcfIrhSFkwEFMZFJOs+0q0ggUMQQkEIkIAJBKhGZdQYRMKQAkIGSGkGAQECADUJwKWJmRphsCAKOkBkpCgcD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:cfc383c3c7c7cfc3
Perceptual Hash:bc759293c58b6998
Difference Hash:3a2e3e363e1b3e37
Wavelet Hash:cf83838387c38fc3
Color Hash:#b279d2

Other Hashes

Crop Resistant:3a2e3e363e1b3e37

Scan History

Scan history not available

Unable to load historical scan data