Security Scan Report: unitranscond.com

Submitted: Oct 1, 2026, 4:25:07 PMCompleted: Oct 1, 2026, 4:25:56 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Legitimate 11-year-old Colombian transport site whose WordPress pages have been compromised with the ErrTraffic/Exvicy injected loader and EtherHiding blockchain-RPC exfiltration (CRITICAL YARA + 7 IDS malware alerts). Do not browse; report and clean.

Risk Factors (5)
Injected ErrTraffic/Exvicy obfuscated JavaScript loader (Base64/XOR + new Function) on a compromised WordPress page
EtherHiding malvertising/exfiltration via blockchain smart-contract RPC calls (7 CRITICAL IDS malware alerts)
Primary domain reported as malware ('clearfake') by threat intelligence
Unranked third-party script host (browseid.codes) injecting code into the page
7 Function() constructor calls indicating runtime code generation
Domain age information unavailable

Details

Page Title

Unitranscond

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'unitranscond.com' is registered with no subdomain. Its registrable label 'unitranscond' stretches across 12 characters with 4 vowels and 8 consonants. Splitting it apart reveals 3 words: uni, trans, cond. Median word length is four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://unitranscond.com/

Page Load Overview

9.26s
Total Load Time
4.5 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es-CO
Text Length:1,988 chars
Detector Agreement:67%

Website Classification

Primary Category

corporate business99% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
99%
government public service
98%
travel tourism
96%
education learning
88%
adult content
84%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
22190.8.176.243Plano, Texas, United States
AS36454WHG Hosting Services Ltd
4142.251.127.95Google · CDNUnited States
AS15169Google LLC
4104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4192.178.183.138Google · CDNUnited States
AS15169Google LLC
4142.251.14.94Google · CDNUnited States
AS15169Google LLC
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4142.251.152.119Google · CDNUnited States
AS15169Google LLC
15033--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DA1409607A91143A212F136FD057B60C21AE8AA3D70D62E5F4FD806487F9FE235E2B5D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:tczeFCZ0iXdjKa1Nz73Y0QsofBlyAb36tetEd2AeYQzqGGBWqgk4xY:SRXdjKa1NHoguk4xY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:201187:DjQh5ZEqqKOQApHUD6CBUGMLLFyFBABxD0oATky0ERAAAZAANwYi7AF6PFgEAASmCFIIIeGwoF1IQo5zbFhWARQirXdJUqGW

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffff0000010000ff
Perceptual Hash:aaa7b528a63b2707
Difference Hash:2f3bd9a96f9b3b0f
Wavelet Hash:ffff00003f0900ff
Color Hash:#2d864f

Scan History

Scan history not available

Unable to load historical scan data