Security Scan Report: circaire.com

Site favicon
Submitted: Sep 19, 2026, 3:47:26 PMCompleted: Sep 19, 2026, 3:47:53 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Legitimate 10-year-old Circaire festival site compromised with the ClickFix FakeCAPTCHA LOLBin kit, EtherHiding exfiltration and exploit-kit C2 — do not follow any on-page 'verification' steps.

Risk Factors (5)
Confirmed ClickFix FakeCAPTCHA (LOLBin) phishing kit injected into the page
Fake Cloudflare 'connection security' verification prompt harvesting user-initiated command execution
EtherHiding exfiltration C2 traffic observed by IDS
Exploit-kit C2 (TA2726 fake WordPress plugin, TA569 Gholoader) active on the page
Multiple threat-intel IoC matches, including the primary domain tagged as a malware loader
Domain age information unavailable

Details

Page Title

CIRCAIRE – FESTIVAL DE CIRC D'ALCÚDIA

Scan Type

public

Domain Name Analysis

The domain name 'circaire.com' uses the commercial generic top-level domain (.com) without a subdomain. The second-level label 'circaire' is 8 characters long with 4 vowels and four consonants. Breaking it apart gives two words: circa, ire. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://circaire.com

Page Load Overview

7.03s
Total Load Time
863 KB
Total Size

Language Analysis

Primary Language

🇪🇸CA
Code: ca
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:ca
Text Length:3,065 chars
Detector Agreement:40%

Website Classification

Primary Category

corporate50% confidence
Type: dynamic
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3217.160.0.48Germany
AS8560IONOS SE
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3104.21.43.2Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.21.3.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
3172.67.130.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3612--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11A33B623B15410AD3A4EABED9085EB1B2175CE211C0F37FD74E1389BE3ADAB60097359

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:eOpx6nljXypI7ykbPaBoMlOyiXyUcT6am4Iass+j:ii/MaYj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:53998:a8gwAS6TzgAGxWpAkqFRQBRJITIBAITNggvwC4VwOGJsIQIwdOJEQIwBIgVAPBBSRhAokDEgNIWAcGJVJ60YrIrVQSTCgwAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffc3c383
Perceptual Hash:b4cb35c08f25d28f
Difference Hash:b20c8c86c0969616
Wavelet Hash:00e7e77e7ec30303
Color Hash:#ac7753

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data