Security Scan Report: twopintplc.com

Site favicon
Submitted: Sep 23, 2026, 6:47:32 AMCompleted: Sep 23, 2026, 6:48:36 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 74%

8
Risk Score

Established education-podcast site showing compromise indicators: a CRITICAL Suricata EtherHiding malware-exfil alert, blockchain RPC gateway queries, and content-malware threat-intel matches on the domain and a loaded resource (xaz2.com). No forms, but treat as infected.

Risk Factors (5)
Critical IDS detection of EtherHiding malware exfiltration traffic
Blockchain RPC domain queries (gateway.tenderly.co) matching EtherHiding behavior
Content-malware indicator against the primary domain (single-source, unverified)
Content-malware indicator against a loaded third-party resource (xaz2.com, 2 feeds)
Established 8-year-old site showing compromise indicators rather than organic malicious content
Domain age information unavailable

Details

Page Title

Two Pint PLC - Personal & Professional Education Podcast

Scan Type

public

Domain Name Analysis

The domain 'twopintplc.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. The core label 'twopintplc' covers 10 characters containing 2 vowels alongside eight consonants. Tokenizing the label suggests 3 words: two, pint, plc. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://twopintplc.com

Page Load Overview

12.42s
Total Load Time
3.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,886 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%
news/blog
40%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.13.95Google · CDNUnited States
AS15169Google LLC
3142.250.154.97Google · CDNUnited States
AS15169Google LLC
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.14.95Google · CDNUnited States
AS15169Google LLC
3192.178.183.97Google · CDNUnited States
AS15169Google LLC
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3146.75.120.134Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
313.226.244.54Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
10632--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BFD22A32D29404D57F1EC7ADB2F2B22CA554B615C9136BA7F0BD30AC49686F700A7A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:z9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyhEFIizGzCWdNJ6Ih754r/ZdSZUaAhHN:z9i5Q62I/xE6x4g5bn/bI2WIZdypa9n

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31011:E1JpCAUQ2W4KghWsSAgHdkkQAfSCCZKDJJYoSp8oAUaUBQ0wAlA9NEVDCF5SDWKurywIoUcYMS+lQxAKIKDZFEQKWIGQDu4Q

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000ffdfffffffff
Perceptual Hash:986e4acbd8b8c8d9
Difference Hash:2b64b8b8b2d0b8b1
Wavelet Hash:99007e1e7a7e4e58
Color Hash:#bf9540

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data