Security Scan Report: alcoawheels.impar.ro

Submitted: Sep 26, 2026, 1:47:25 AMCompleted: Sep 26, 2026, 1:48:06 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate-looking 24-year-old Alcoa Wheels dealer page, but clear signs of compromise: 11 CRITICAL EtherHiding malware IDS alerts, blockchain RPC C2 traffic, and a malicious third-party script — likely serving malware.

Risk Factors
Network IDS critically flags EtherHiding malware exfiltration (x11)
Page establishes blockchain RPC connections consistent with EtherHiding C2
Malicious third-party script/domain (idcool.codes) loaded by the page
Primary domain itself carries a single-source malware classification
Domain age information unavailable

Details

Page Title

Alcoa Wheels

Scan Type

public

Domain Name Analysis

Domain 'alcoawheels.impar.ro' uses the Romanian country-code top-level domain (.ro), featuring subdomain 'alcoawheels'. The second-level label 'impar' is 5 characters long containing two vowels alongside 3 consonants. Splitting it apart reveals 2 words: im, par. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://alcoawheels.impar.ro

Page Load Overview

8.93s
Total Load Time
4.4 MB
Total Size

Language Analysis

Primary Language

🇷🇴Romanian
Code: ro
Confidence:65%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:21,814 chars
Detector Agreement:67%
Language mismatch: Declared as en-US but detected as ro

Website Classification

Primary Category

corporate business70% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
70%
documentation technical
69%
adult content
43%
government public service
41%
education learning
35%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1284.1.113.213Bucharest, Bucharest, Romania
AS5483Magyar Telekom Plc.
7142.251.13.95Google · CDNUnited States
AS15169Google LLC
7104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.127.94Google · CDNUnited States
AS15169Google LLC
7152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
735.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
7178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
10314--

Detected Technologies7

WordPressv4.9.3
100%
JQueryv1.12.4
100%
Bootstrapv2.0.2
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T156E32D535384033BE28508D2E214352BA6F1D14BF935614CBBEFA9FFFB6D8825436626

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Vr0oZPXxnDaGzem8jeUsA92lIzDY0XSRbz8HHy7sFohpgtHHdsYvBlYywPIzwsST:CoZaO8zKRbgyIPndsYvBldwPIc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:154712:OATAhKRsTgQA0AaW8gCJcgiTsgeMDg6AQkFRhLUCQAEYG1KCZNDCBZpBRBA0AqAQa4gClaknXHAIQElBST0IAIAcDOgAGmUQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:080c7001030fffff
Perceptual Hash:8e42d1112dece2fd
Difference Hash:d8f1e5a33fbd3747
Wavelet Hash:0c1c7001031fffff
Color Hash:#86642d

Scan History

Scan history not available

Unable to load historical scan data