Security Scan Report: prophysis-sr.de

Site favicon
Submitted: Sep 21, 2026, 7:47:30 AMCompleted: Sep 21, 2026, 7:47:51 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Established German physiotherapy site appears compromised: critical EtherHiding malware IDS alert, multi-source xaz2.com malware Indicators of Compromise, and primary-domain RAT report. Avoid interaction.

Risk Factors
Critical IDS alert indicating malware/network trojan activity.
Multi-source malware Indicators of Compromise on a loaded third-party domain (xaz2.com).
Primary domain itself reported as unknown RAT malware.
Outbound link to a domain reported as an unknown malware loader.
Crypto/blockchain-related external resource and JS API use aligned with EtherHiding exfiltration.
Domain age information unavailable

Details

Page Title

© Gesundheitspraxis Prophysis

Scan Type

public

Domain Name Analysis

Domain 'prophysis-sr.de' uses the German country-code top-level domain (.de) with no subdomain. Count 12 characters in 'prophysis-sr' with 2 vowels and nine consonants, along with one hyphen. Splitting it apart reveals 5 words: prop, hy, s, is, sr. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://prophysis-sr.de

Page Load Overview

3.18s
Total Load Time
2.2 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:2,869 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
100%
social media network
57%
adult content
44%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
781.169.145.86Germany
AS6724Strato GmbH
7148.251.5.29Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
7172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
284--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13CD095CF1C03D2034DE4F2C83564E70C845DD9DBB411D901BEC009402EDB7590C11140

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:h4hqGBY/E5VOkXzHrzcE/NpLVUSRMDWHDYH4MwFMFtpuB9d:h4QE5DXzLXpLhg4jFMFvG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:ff068b04b00e9497f52874ae49065408

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ff003c18ffdfdf
Perceptual Hash:9a43b4e54f4e233a
Difference Hash:329de96969163737
Wavelet Hash:002d003c18ffdfdf
Color Hash:#ac6553

Scan History

Scan history not available

Unable to load historical scan data