Security Scan Report: ethena.fi

Site favicon
Submitted: Sep 26, 2026, 2:56:11 PMCompleted: Sep 26, 2026, 2:56:52 PMpubliccompleted

This website contacted 22 IPs in 3 countries across 11 domains to perform 154 HTTP transactions. The main domain is ethena.fi and was registered 3 years 5 months ago.

Submitted URL: https://ethena.fi

The Cisco Umbrella rank of the primary domain is #924,687 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 60%

7
Risk Score

Ethena's own well-established DeFi site with no forms or impersonation; blockchain RPC traffic triggered a critical 'EtherHiding' IDS signature likely a false positive, but on-chain exfil alerts warrant caution. Not confirmed phishing or malware.

Risk Factors (3)
CRITICAL Suricata alert 'ET MALWARE EtherHiding Exfil M2' (network-trojan category) on blockchain RPC traffic
CRITICAL Suricata alert 'ET INFO Possible ethereum traffic' and MEDIUM blockchain-RPC DNS/TLS signatures
Page loads external blockchain RPC endpoints (eth.drpc.org, api.avax.network, avalanche.drpc.org) which are the likely trigger for the malware-class signatures
Domain age information unavailable

Details

Page Title

Ethena - Digital Dollars for the Internet Economy

Scan Type

public

Domain Name Analysis

The domain name 'ethena.fi' uses the Finnish country-code top-level domain (.fi) without a subdomain. Count 6 characters in 'ethena' holding 3 vowels versus three consonants. Tokenizing the label suggests 3 words: e, then, a. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ethena.fi

Page Load Overview

6.79s
Total Load Time
3.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:5,336 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7216.230.86.1Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
744.223.208.125Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
7172.66.166.164Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
73.41.202.167Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
7104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.36.169Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.43.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
74.208.245.14Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
735.174.221.176Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
15422--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FFB308766100EDA762178DD834B1EF4BD15EE32ACE36DC48A3ECC66A17D2CF0CA51958

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:DxGWMMMcQKyHaWod5BjyQLQcSYeAGsEPhnnZCpQ:DxdHQKyHa/vE+innZCa

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:111654:KDOk4SEwjYjgfEVAuVCVAHQAkOE4AzaskC5GKBTipJCAiBpYJJOEkJIxWSodIgAgEEIQkNOUQlBgCMJKZJoZQfuKgHKhChFI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f183c080000147c
Perceptual Hash:9c9c96b3b2929e8c
Difference Hash:ec30701020285555
Wavelet Hash:ff183c1818043dff
Color Hash:#651f93

Other Hashes

Crop Resistant:ec30701020285555

Scan History

Scan history not available

Unable to load historical scan data