Security Scan Report: womenindev.com

Site favicon
Submitted: Sep 16, 2026, 2:47:30 AMCompleted: Sep 16, 2026, 2:48:28 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

9
Risk Score

Legitimate 7-year-old Women in Dev WordPress site that has been compromised with ClearFake/EtherHiding malware; CRITICAL IDS alerts and blockchain RPC payload delivery mean visitors risk malware infection — avoid.

Risk Factors
ClearFake malware indicator on the primary domain (threatfox.abuse.ch)
EtherHiding/ErrTraffic exploit-kit IDS alerts marked CRITICAL (network trojan detected)
Blockchain RPC domains used for payload delivery/exfiltration (EtherHiding technique)
Multiple malware-flagged external resources loaded by the page (cloudflare-check.net, qaz0.com, aleverifocation.beer, rehearsal-b.com)
Compromised WordPress installation serving injected malicious scripts
Domain age information unavailable

Details

Page Title

Women in Dev – Uniting women to drive change

Scan Type

public

Domain Name Analysis

Domain 'womenindev.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Count 10 characters in 'womenindev' split between four vowels and six consonants. Tokenizing the label suggests 3 words: women, in, dev. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://womenindev.com

Page Load Overview

26.10s
Total Load Time
11.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:5,573 chars
Detector Agreement:100%

Website Classification

Primary Category

forum40% confidence
Type: spa
Method: structural

All Detected Categories

forum
40%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14172.217.112.4Google · CDNUnited States
AS15169Google LLC
5217.160.0.117Germany
AS8560IONOS SE
5142.251.127.95Google · CDNUnited States
AS15169Google LLC
5142.251.150.119Google · CDNUnited States
AS15169Google LLC
5142.251.157.4Google · CDNUnited States
AS15169Google LLC
5142.251.153.4Google · CDNUnited States
AS15169Google LLC
5142.251.155.119Google · CDNUnited States
AS15169Google LLC
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5142.251.156.4Google · CDNUnited States
AS15169Google LLC
5142.251.20.155Google · CDNUnited States
AS15169Google LLC
20439--

Detected Technologies13

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19C32E87243CB39C29E2C9922BBB9D15C0205A4372537BD6BC14A7F9C702A7AF8444CDB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:PYliMULjSak0mqUeFXtHcaNqZh3TqzgmzHz8Cl8XVe96bJh8QlC9:wdUqQm0PIlGDzHz8CMe9ihpO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11573:qA0AKRALIChYSKCKAQKwOaAgUZMBHJoAQ1kFggBUoAiZDGLkIvYQ2KHMjmIGkAkhjbQSOCs5LlALQEgCBsBQspBBF0NEYGNA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0001010101010101
Perceptual Hash:aa5555557755cc88
Difference Hash:0001010909010101
Wavelet Hash:0e0f1f0f0f0f0f0f
Color Hash:#73862d

Other Hashes

Crop Resistant:0001010909010101

Scan History

Scan history not available

Unable to load historical scan data