Security Scan Report: yypost-main.net

Site favicon
Submitted: Sep 14, 2026, 5:47:44 PMCompleted: Sep 14, 2026, 5:48:20 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Page's own domain is flagged for malware and it generates exploit-kit/EtherHiding exfiltration traffic to blockchain RPC nodes — active malware distribution despite its benign shipping-service facade.

Risk Factors (5)
Critical malware and exploit-kit IDS alerts (EtherHiding exfiltration, ErrTraffic check-in)
Blockchain RPC connections used for payload hosting/exfiltration
Primary domain flagged in a malware threat-intel feed
Heavy use of Function() constructor for runtime code generation
HIGH ET DROP Spamhaus listed traffic
Domain age information unavailable

Details

Page Title

YYPOST | 韓国からの配送をお手伝いいたします

Scan Type

public

Domain Name Analysis

The domain 'yypost-main.net' uses the network infrastructure generic top-level domain (.net) while skipping any subdomain. Its registrable label 'yypost-main' stretches across 11 characters with 3 vowels and seven consonants, notching one hyphen. Breaking it apart gives 3 words: yy, post, main. Median word length is 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://yypost-main.net

Page Load Overview

14.93s
Total Load Time
7.8 MB
Total Size

Language Analysis

Primary Language

🇯🇵Japanese
Code: ja
Confidence:80%
Script:Mixed
Direction:ltr

Detection Details

HTML Lang Attribute:ja
Text Length:1,051 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network62% confidence
Type: spa
Method: ml+structural

All Detected Categories

social media network
62%
government public service
46%
documentation technical
35%
technology software
32%
e-commerce shopping
26%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
29202.233.67.109Japan
AS131965Xserver Inc.
674.125.29.95Google · CDNUnited States
AS15169Google LLC
6202.226.37.225Japan
AS131965Xserver Inc.
6172.217.116.4Google · CDNUnited States
AS15169Google LLC
6142.251.110.94Google · CDNUnited States
AS15169Google LLC
6104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6142.251.151.119Google · CDNUnited States
AS15169Google LLC
6178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
6172.217.117.4Google · CDNUnited States
AS15169Google LLC
20330--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BE53DE72C46E3CEB07F587AD7A0AA940D3ECF146DF05CF81B66D106DD2D465422B3AA8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:hjYQyUHppxRBhBRhpx4BxwrqrZdapWjJk9eo6V2:KQyiroapl

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:65318:hxgsTABKWoGArATWAJAJIA9CIQUHDQgwGAJyXQFAVHlA24FAsSACIQAAMGyAUQhAsAwBU4sA1B44eJwgkKAiUV0TrBEgU1AO

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffd7c78fcfff00
Perceptual Hash:b83c4e1838fc3cbc
Difference Hash:36c016161818c00d
Wavelet Hash:00fed3838f8ffe00
Color Hash:#d279b9

Other Hashes

Crop Resistant:36c016161818c00d

Scan History

Scan history not available

Unable to load historical scan data