Security Scan Report: lampaa.ir

Site favicon
Submitted: Sep 15, 2026, 3:47:32 AMCompleted: Sep 15, 2026, 3:47:58 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Legitimate-looking Iranian robotics school, but a critical EtherHiding malware IDS alert, blockchain RPC connection, and two malware threat-intel matches (primary domain and loaded xaz2.com) indicate compromise/malicious injection.

Risk Factors (5)
Domain registered 11 days ago (VERY_NEW, 2x multiplier)
Critical Suricata malware alert on page traffic
Blockchain RPC connection consistent with EtherHiding exfiltration
Two malware-type threat-intel matches (one against the primary domain, one against a loaded resource)
Site claims 'over ten years of experience' while the domain is only 11 days old (content/age mismatch)
Domain age information unavailable

Details

Page Title

آموزشگاه رباتیک و برنامه‌نویسی لمپا - آموزش برنامه‌نویسی و رباتیک

Scan Type

public

Domain Name Analysis

The domain 'lampaa.ir' uses the Iranian country-code top-level domain (.ir) while skipping any subdomain. The core label 'lampaa' covers 6 characters split between three vowels and three consonants. Segmentation suggests 3 words: lamp, a, a. The median word length lands at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lampaa.ir

Page Load Overview

4.47s
Total Load Time
14.5 MB
Total Size

Language Analysis

Primary Language

🇮🇷Persian
Code: fa
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:fa-IR
Text Length:21,812 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking69% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
69%
education learning
52%
technology software
51%
documentation technical
38%
corporate
35%

Detected Features

Comments
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
27185.8.174.60Iran
AS60631Vandad Vira Hooman LLC
26188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
26172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
793--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T128B22BF2435958B24AB4D692BFB3782C4B23690B99126E83F05E0E9C0FB54D3534E877

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:/3o+8ccjyhVmGenZ93lMsqy6rF73uhtZlPxCKiU69fNwMKDfNQ62Ho/xE6x4aUgO:/3o+8ccMUnZ93lMsqRNv9i5Q62I/xE66

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23973:cEvCIIIA0oACzCAhlCQB4giSruGQS4cmR69LAEbAWBQIBBkCyc0WBogMmkUSUJxCuAowEgcDgaHSDMEDA5QRJYhCQCBJAFQB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffc3fbfff7ffff
Perceptual Hash:e94312524f6d7d32
Difference Hash:d0881b024a0e062a
Wavelet Hash:00c7c1c3fbe3c3c3
Color Hash:#692dd2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data