Security Scan Report: edumenezes.com.br

Site favicon
Submitted: Sep 20, 2026, 2:47:25 AMCompleted: Sep 20, 2026, 2:48:01 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate solar-energy site apparently compromised with ClearFake/EtherHiding malware: CRITICAL EtherHiding exfil IDS alerts, blockchain RPC payload retrieval, and ClearFake-flagged third-party resources. Do not interact.

Risk Factors (5)
CRITICAL IDS malware alerts indicating EtherHiding exfiltration (ClearFake)
Blockchain RPC connections used to retrieve malicious payloads (EtherHiding technique)
Third-party resources on the page flagged as ClearFake malware infrastructure
Primary domain flagged in threat intel (iclickfix, single-source)
Heavy obfuscated JavaScript (Function() constructor, encoding/decoding routines)
Domain age information unavailable

Details

Page Title

RHL Energias Renováveis – Gestão de Obras, Instalações, O&M em Usinas Fotovoltaicas

Scan Type

public

Domain Name Analysis

You're looking at domain 'edumenezes.com.br' on the Brazilian country-code top-level domain (.com.br) with no subdomain. Its registrable label 'edumenezes' stretches across 10 characters holding five vowels versus five consonants. Tokenizing the label suggests 2 words: edu, menezes. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://edumenezes.com.br

Page Load Overview

15.49s
Total Load Time
12.6 MB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-BR
Text Length:4,580 chars
Detector Agreement:75%

Website Classification

Primary Category

documentation technical96% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
96%
government public service
84%
adult content
59%
corporate business
44%
real estate property
44%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
21162.241.2.183Vinhedo, São Paulo, Brazil
AS31898Oracle Corporation
11104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11142.251.13.95Google · CDNUnited States
AS15169Google LLC
11104.18.1.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1135.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
11172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11142.251.14.95Google · CDNUnited States
AS15169Google LLC
11104.18.0.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
15313--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1ED834A7122024EB64FFE07E9C2CA20E4DCEA15D56A85F2FD195E51CC0B16EB7616CA3C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:XgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgCgGFypb2T:XgCgCgCgCgCgCgCgCgCgCgCgCgCgCgC9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:87731:A9RQFDbQAkGsBQADSI4RYQACFAIQmJB4iMvq2YwAzU6VpihtAka5IbE5QEApRIpKiAEgghMDLAYgoCBYoQACUAAADrFUI0IJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff063020002000ff
Perceptual Hash:8714b873b946c71e
Difference Hash:dcb4e4cecaca6252
Wavelet Hash:ff5f7622206000ff
Color Hash:#d2797e

Scan History

Scan history not available

Unable to load historical scan data