Security Scan Report: harapouya.ir

Site favicon
Submitted: Sep 18, 2026, 3:47:25 PMCompleted: Sep 18, 2026, 3:48:08 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Newly registered site hosts an analyst-vetted ClickFix fake-CAPTCHA malware kit with a LOLBin payload, EtherHiding C2 exfiltration and exploit-kit traffic — do not visit or interact.

Risk Factors
ClickFix fake-CAPTCHA malware kit serving a LOLBin (msiexec/mshta/wmic) payload
EtherHiding C2 exfiltration over blockchain smart-contract infrastructure
ErrTraffic exploit-kit traffic cluster
Multiple malicious third-party domains loaded by the page (aleverifocation.beer, clickzona.net, cloudflare-check.net)
Domain is 4 days old and unranked (weak prior, but paired with concrete malware signals)
Domain age information unavailable

Details

Page Title

مهندسین مشاور حرا پویای بندر – طراحی،نظارت،مقاوم سازی

Scan Type

public

Domain Name Analysis

Within the Iranian country-code top-level domain (.ir), 'harapouya.ir' is registered and has no subdomain. The core label 'harapouya' covers 9 characters split between 5 vowels and 4 consonants. Tokenizing the label suggests 4 words: hara, po, u, ya. Expect two characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://harapouya.ir

Page Load Overview

24.15s
Total Load Time
1.3 MB
Total Size

Language Analysis

Primary Language

🇮🇷Persian
Code: fa
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:fa-IR
Text Length:40,849 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software60% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
60%
documentation technical
56%
cryptocurrency blockchain
45%
news media journalism
44%
entertainment media
43%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1245.139.11.132Iran
AS60631Vandad Vira Hooman LLC
5150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
5104.21.3.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5172.217.119.4Google · CDNUnited States
AS15169Google LLC
5104.21.43.2Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5172.217.114.4Google · CDNUnited States
AS15169Google LLC
5178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
5142.251.127.94Google · CDNUnited States
AS15169Google LLC
5104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10720--

Detected Technologies12

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115432C6092571CDB7B36C15F01C0BFA4566BAF02D9458A26F4BA267CC5B80E700AEF7D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:5uiPdb58H7hW4akqPIjqvu0Jz+mQPMSjW39Zdyp63:RPdWH7hWnkqPIjqvfDQPFjW3Vypo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:55863:KsGCIBIGEQYBAcQhWoAU2hsgJpDQWSYKESgDBIEIjyOwRQuacAUw4kSATQGgDKzWeBg4KKB2AB2OBUEkZSAGCgCAI/CAab0y

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:80c0808080c08080
Perceptual Hash:ff7f41002fae8f00
Difference Hash:4404602545010141
Wavelet Hash:80e0a8b5f3ffa981
Color Hash:#d22dbc

Other Hashes

Crop Resistant:4404602545010141

Scan History

Scan history not available

Unable to load historical scan data