Security Scan Report: dein-sandmann.de

Site favicon
Submitted: Oct 1, 2026, 1:04:45 PMCompleted: Oct 1, 2026, 1:05:32 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Long-standing German sleep-help site has been compromised and injected with the Macfinger ClickFix/ErrTraffic Exvicy loader kit; CRITICAL YARA and IDS malware alerts plus EtherHiding blockchain RPC exfiltration make it actively malicious.

Risk Factors (5)
Analyst-vetted malicious kit roster match: Macfinger ClickFix stealer (shared loader t.4b1009ff6c3f.js) and ErrTraffic/Exvicy injected WordPress loader
Critical network IDS malware/C2 alerts (AMOS ClickFix loader, EtherHiding exfiltration)
Blockchain RPC connection (rpc-mainnet.matic.quiknode.pro) alongside obfuscated loader — EtherHiding technique
Threat-intel match on the primary domain (malware/clearfake, 2 independent feeds)
Obfuscated JavaScript executed via Function() constructor on a content site with no legitimate need for it
Domain age information unavailable

Details

Page Title

Dein Sandmann.de – Einschlafen leicht gemacht

Scan Type

public

Domain Name Analysis

You're looking at domain 'dein-sandmann.de' on the German country-code top-level domain (.de) with no subdomain. The second-level label 'dein-sandmann' is 13 characters long containing four vowels alongside 8 consonants, plus one hyphen. It segments into 3 words: de, in, sandmann. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dein-sandmann.de/

Page Load Overview

7.52s
Total Load Time
603 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:29,412 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content37% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
37%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3185.30.32.198Germany
AS48324webgo GmbH
374.125.29.95Google · CDNUnited States
AS15169Google LLC
385.192.25.209Helsinki, Uusimaa, Finland
AS210644Aeza Group LLC
3150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3172.67.171.128Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3104.21.95.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
248--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T162B3E87268813037021F1DD2A1127BB9F6A3C209C753145AD7BAF75F9BD5FA2CAA190C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ejWncquMtWvqXi0c2nGmWMt2aLyaFfqvOFVwB9uKQt9mt9wGIZ/Xootj5U8i2Zvh:cYcaNl3ikps/S3hEsqRYxI+Ntf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:118046:jLUVgtiipTNA1TJipGKFCZVAwEi0IMIJwlasNYDoAAIDJigSnCABwCKB8LDB4BQqLM0Rh8A4ARlrK4AwBUsigChhxEb3CFc6

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fe0000000000f000
Perceptual Hash:cad2d2d2d2d2d2d2
Difference Hash:31c549490dc11121
Wavelet Hash:ffe0e0e0c1f1f980
Color Hash:#936b1f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data