Security Scan Report: www.local7.it

Site favicon
Submitted: Oct 4, 2026, 10:25:11 AMCompleted: Oct 4, 2026, 10:25:48 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Compromised WordPress site injecting a fake Cloudflare 'Human Verification' ClickFix overlay; vetted kits and CRITICAL YARA/IDS hits show it tricks visitors into pasting attacker commands in Terminal. Do not interact.

Risk Factors (5)
Compromised WordPress site serving an injected ClickFix social-engineering overlay (fake Cloudflare 'Human Verification' page)
Two analyst-vetted CRITICAL malicious kits confirmed by name and family (ErrTraffic/Exvicy loader, ClickFix Win+X overlay)
Instructs users to open a terminal and paste attacker-supplied commands (Ctrl+V then Enter) — remote code execution / malware delivery
Blockchain RPC connections used for EtherHiding-style payload retrieval, corroborated by 9 CRITICAL IDS exfiltration alerts
Threat-intel Indicators of Compromise on the primary domain ('clearfake' malware, 2 independent feeds) and on loaded third-party resource domains
Domain age information unavailable

Details

Page Title

Local7

Scan Type

public

Domain Name Analysis

Domain 'www.local7.it' uses the Italian country-code top-level domain (.it) and includes subdomain 'www'. The second-level label 'local7' is 6 characters long with two vowels and 3 consonants, notching 1 digit. It segments into 2 words: local, 7. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.local7.it/

Page Load Overview

3.20s
Total Load Time
322 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:it-IT
Text Length:652 chars
Detector Agreement:100%
Language mismatch: Declared as it-IT but detected as en

Website Classification

Primary Category

technology software47% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
47%
cryptocurrency blockchain
41%
documentation technical
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
689.46.110.62Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
235.214.244.104Google · CDNGroningen, Groningen, Netherlands
AS43515Google Ireland Limited
2132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
2152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
2104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.66.146.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
2172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2611--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D530A3393A0416E375D47ED8062F21B69F4E6118D2D62A977E170DEE91C5F3007AF1A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ekXhaU5ypE+D/UbHIibCWfGbgvhhz3zAOWLR08:OU0+Y/UbHIwjDAOWLK8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:61896:OIIssoBDFkIoABissLU5igCwPRAnAy50AkCiAQYQIIehpBGAbiIMEBAAACCGqOK/RAAEeKJJwTgEXEQxhyyUaBAwyGE5diQQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fcfce0f0e0c0e0e0
Perceptual Hash:f7889a33cc8d3386
Difference Hash:00000416040c0204
Wavelet Hash:fefcf0f0e0c0e0e0
Color Hash:#e06c6c

Other Hashes

Crop Resistant:00000416040c0204

Scan History

Scan history not available

Unable to load historical scan data