Security Scan Report: nectarclinic.com

Site favicon
Submitted: Sep 20, 2026, 10:47:31 PMCompleted: Sep 20, 2026, 10:48:32 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate clinic site likely compromised, serving EtherHiding malware via Ethereum RPC and malicious third-party resource; avoid interaction.

Risk Factors
Threat-intel match on primary domain (unknown rat malware)
Multi-source IoC on loaded resource xaz2.com (iclickfix malware)
Critical network IDS alert for EtherHiding exfiltration
Communications with Ethereum RPC endpoint 0xrpc.io (EtherHiding indicator)
Domain age information unavailable

Details

Page Title

NectarCLINIC Xàtiva, Clínica Estética

Scan Type

public

Domain Name Analysis

The domain name 'nectarclinic.com' uses the commercial generic top-level domain (.com). The second-level label 'nectarclinic' is 12 characters long containing 4 vowels alongside eight consonants. Splitting it apart reveals two words: nectar, clinic. Median word length comes out to six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nectarclinic.com

Page Load Overview

17.39s
Total Load Time
6.0 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:7,157 chars
Detector Agreement:80%

Website Classification

Primary Category

healthcare medical68% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
68%
adult content
66%
news media journalism
41%
government public service
38%
corporate
25%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2791.146.102.78Orihuela, Valencia, Spain
AS198066Grupo Loading Systems, S.L.
10142.251.13.95Google · CDNUnited States
AS15169Google LLC
10142.250.154.101Google · CDNUnited States
AS15169Google LLC
10142.251.156.119Google · CDNUnited States
AS15169Google LLC
1013.33.187.28Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
10142.251.20.100Google · CDNUnited States
AS15169Google LLC
10142.251.155.119Google · CDNUnited States
AS15169Google LLC
1013.33.187.25Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
10146.19.24.104Poland
AS201814MEVSPACE sp. z o.o.
10188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21720--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B042F8B1839669D42E6CEA01BBF6B96C0741A83B64337DDBC10F9D8D24398DB9045CD7

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:pggTlXbDN6BMD+gkdJfVzf4sJ2HQn/xE6oAi5a8zlvg/dP/xB/nkWHHDZUs:SG9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12213:dcuCgK2DECQJFAIDmEhYRIiA8VlAgGEEieAEZKJqgUJkQJ4ViQIGxs6IGXowCAZCyIAYjDkkoHrCJQRKxZBAEikMhTBREAgw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00bffffff7ff5bff
Perceptual Hash:9f1f1f1f66606160
Difference Hash:65719a555540aaaa
Wavelet Hash:000fc3ff00ff425b
Color Hash:#2dd28d

Other Hashes

Crop Resistant:65719a555540aaaa

Scan History

Scan history not available

Unable to load historical scan data