Security Scan Report: check.first-node.rocks

Submitted: Sep 14, 2026, 1:48:07 AMCompleted: Sep 14, 2026, 1:49:43 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Hostname is a multi-feed 'wp inject' malware/exploit-kit gate (ErrTraffic) confirmed by 2 CRITICAL IDS alerts. Placeholder nginx page masks active infection infrastructure — avoid entirely.

Risk Factors (4)
Multi-source corroborated malicious domain reputation (wp inject) on the exact scanned hostname
CRITICAL IDS classification as Exploit Kit / ErrTraffic gate domain
Domain only 191 days old with zero reputation (unranked in Cisco Umbrella)
Placeholder nginx page inconsistent with reported malicious infrastructure, suggesting a gated/conditional payload
Domain age information unavailable

Details

Page Title

Welcome to nginx!

Scan Type

public

Domain Name Analysis

You're looking at domain 'check.first-node.rocks' on the .rocks top-level domain with subdomain 'check'. The registrable portion 'first-node' spans 10 characters holding 3 vowels versus six consonants; bonus characters include one hyphen. Word splitting yields 2 words: first, node. Expect 4.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://check.first-node.rocks

Page Load Overview

2.60s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

Text Length:291 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software33% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AEF0029BF3402117B88343013CB36A213B5403E40314CB6578C70DD6DF2A923F427574

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:haxnp/ILjFBt0FSMpsvZJD64xxaboR1XKCf0ktEjo+Y/lNQd30UlNRVxWUOj:haRpEF7D6GJ+tsvXD05oP/l8kUlj7Wbj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:612:AAAgAAAAgAAAgAAAAAAAAAAAAAAAAAAAAAAAAgAAAAAAAIAAAgACAABAAAAgAAAAIACEAAAAAAAAQAAAAAABAAABAAAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c7ffffffffffff
Perceptual Hash:b33333333389cccc
Difference Hash:1c1c000000000000
Wavelet Hash:07073f3f00000000
Color Hash:#e06cbf

Other Hashes

Crop Resistant:1c1c000000000000

Scan History

Scan history not available

Unable to load historical scan data