Security Scan Report: thecureofatlantis.com

Site favicon
Submitted: Oct 1, 2026, 1:04:36 PMCompleted: Oct 1, 2026, 1:05:53 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate-looking medical supplier page whose own domain is flagged as malware and whose scripts trigger 7 critical EtherHiding malware-exfil alerts plus blockchain RPC C2 traffic — treat as compromised/malicious.

Risk Factors (6)
Primary domain matched as content malware (iclickfix) in threat intel
7 CRITICAL IDS alerts for ET MALWARE EtherHiding Exfil M2
Blockchain RPC connections consistent with EtherHiding C2/payload retrieval
Third-party resource IP flagged as malware by two independent feeds
Unranked third-party script host (browseid.codes) injecting code
Function() constructor code generation on a content site
Domain age information unavailable

Details

Page Title

The Cure of Atlantis for Medical Services - Complete Medical & Diagnostic Solutions for Healthcare Providers

Scan Type

public

Domain Name Analysis

The domain 'thecureofatlantis.com' uses the commercial generic top-level domain (.com) and has no subdomain. Its registrable label 'thecureofatlantis' stretches across 17 characters split between 7 vowels and ten consonants. Breaking it apart gives 4 words: the, cure, of, atlantis. Expect 3.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://thecureofatlantis.com/

Page Load Overview

31.62s
Total Load Time
8.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:7,687 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical86% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
86%
corporate
35%
news/blog
20%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1650.6.43.34Mumbai, Maharashtra, India
AS31898Oracle Corporation
6104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6172.217.208.95Google · CDNUnited States
AS15169Google LLC
6172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.251.14.94Google · CDNUnited States
AS15169Google LLC
6188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
674.125.29.95Google · CDNUnited States
AS15169Google LLC
6104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6172.64.147.103Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10616--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BE44A4613A5A183A315F22CFD017324D61D7DFEAE652A6E8F7F32164A1B4CC037A3265

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:zo3i8pA7pV9KvwOaa8FCxZyQnPvs13JSJnv9ndWfUThGqTnBRci:zIS7pV9wwOaa8FCxMQnZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:266345:Ik0G5IQARr7CAQDONwUAGUUyIADwFkY5NAUIS2g9NgC7YAhJgWDoYSkqUcKKiDSAjUiETCVEAUWKCcAgIU/4xQIAFUsoYDCC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fda9b181a191e7ff
Perceptual Hash:eb0f914af4b0ccc5
Difference Hash:195b63236b230b1c
Wavelet Hash:fd81c1818191e5ff
Color Hash:#2d8649

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data