Security Scan Report: peatsorbng.azurewebsites.net

Submitted: Sep 12, 2026, 6:13:43 PMCompleted: Sep 12, 2026, 6:14:32 PMpubliccompleted

Summary

This website contacted 6 IPs in 2 countries across 6 domains to perform 2 HTTP transactions. The main domain is peatsorbng.azurewebsites.net and was registered 8 years ago.

Submitted URL: https://peatsorbng.azurewebsites.net

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate-looking spill-response page running on a shared host, but its own domain is flagged as a malware loader and the page loads exploit-kit/blockchain-RPC infrastructure with a CRITICAL EtherHiding exfiltration alert — likely compromised and distributing malware.

Risk Factors
Primary domain matched as a malware loader in threat intelligence
CRITICAL Suricata signature for EtherHiding malware exfiltration
Multi-feed exploit-kit resource (fingerprint-veri.info) injected into the page
Suspicious blockchain RPC / smart-contract calls consistent with hidden payload delivery
Function() constructor calls and inline encoding/decoding functions in page scripts
Hosted on shared abuse-prone platform (.azurewebsites.net) with unknown subdomain age
Domain age information unavailable

Details

Page Title

Peatsorbn

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(50%)

Domain Information

Within the network infrastructure generic top-level domain (.net), 'peatsorbng.azurewebsites.net' is registered; it also runs on subdomain 'peatsorbng'. The core label 'azurewebsites' covers 13 characters split between 6 vowels and 7 consonants. Tokenizing the label suggests two words: azure, websites. Median word length is 6.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://peatsorbng.azurewebsites.net

Page Load Overview

25.35s
Total Load Time
96
HTTP Requests
6
Domains
180 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:2,696 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: spa
Method: structural

All Detected Categories

corporate
50%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1620.118.56.12Azure · CLOUDDes Moines, Iowa, United States
AS8075Microsoft Corporation
16150.171.110.54Azure · CLOUDUnited States
AS8075Microsoft Corporation
16142.251.14.94Google · CDNUnited States
AS15169Google LLC
16192.178.183.94Google · CDNUnited States
AS15169Google LLC
16132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
16178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
966--

Page Statistics

96
Requests
6
Unique Domains
657.6 KB
Total Size

Detected Technologies13

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17C61A59349089C1B53B98215A48D708CD239C454D344DC70BBB8478E6ECBAACE17722A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:J5pbYCMAc3VkX1XrgNxJokc3VkX1EooXVfAjrjgrjQV5yVzKyIipsapyHox2x5:WCM53if3iYVfI3gSazKyIDHox2x5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3305:EAABAAACAAICwAAIBAAAUUAYAAAkBoyEAAAjCAQEBABAKAEJAAMgAQAACgAIEAwAAlYhABUIBCBAAgAABAAIBIABCAgAAAKA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff070707fffff800
Perceptual Hash:b63649c9c927c9c9
Difference Hash:2c2c2d2d2c00c1c0
Wavelet Hash:0f070707ffff7000
Color Hash:#1f9353

Scan History

Scan history not available

Unable to load historical scan data