Security Scan Report: dinao.store

Redirected to:
https://www.dinao.store/
Submitted: Sep 16, 2026, 12:47:31 AMCompleted: Sep 16, 2026, 12:49:28 AMpubliccompleted

This website contacted 13 IPs in 4 countries across 13 domains to perform 127 HTTP transactions. The main domain is dinao.store and was registered 18 years ago.

Submitted URL: https://dinao.store

Effective URL:

https://www.dinao.store/
Redirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Legitimate 4-year-old cycling store apparently compromised — page loads blockchain/EtherHiding malware, matching ClearFake Indicators of Compromise and CRITICAL ET MALWARE IDS alerts. Avoid interacting.

Risk Factors
CRITICAL IDS alerts for EtherHiding exfiltration malware on a WordPress site
Multi-source corroborated 'clearfake' malware Indicators of Compromise on loaded blockchain resources
Blockchain RPC connections combined with obfuscated crypto JavaScript (wallet-drainer/EtherHiding infrastructure)
Domain unranked in Cisco Umbrella (no established web reputation)
Domain age information unavailable

Details

Page Title

Ridley Bicycles, South Africa - Dinao Store

Scan Type

public

Domain Name Analysis

You're looking at domain 'dinao.store' on the .store top-level domain without a subdomain. The registrable portion 'dinao' spans 5 characters containing 3 vowels alongside two consonants. It segments into two words: dina, o. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dinao.store

Page Load Overview

90.68s
Total Load Time
830 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-ZA
Text Length:4,065 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce shopping76% confidence
Type: spa
Method: ml+structural

All Detected Categories

e-commerce shopping
76%
documentation technical
66%
adult content
42%
government public service
41%
corporate
35%

Detected Features

Login Form
Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
19162.159.137.54Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9142.251.13.95Google · CDNUnited States
AS15169Google LLC
9102.218.215.35South Africa
AS329184Host Africa (Pty) Ltd
92.18.68.4Akamai · CDNVienna, Vienna, Austria
AS16625Akamai Technologies, Inc.
9188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
9172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9162.159.136.54Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
12713--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11DC2A473E11A502B7B4E67ACB0DBB61A9E899505E501EF7ABCF8101DC7EC1F600AB50D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:Et3nZdypa9SAfAnAhA5M8PyVOdv8y+LI/smRK:K/ypgYA6FP9dv8y+LI/sv

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28274:UQyIEmsWUWRQDQKYFGjArVGABAkQAMJIxCC5AMBQZqA4hQ4HwBIWAxAwYEqYJJCQDkKFNmHCVCIYEAP+BqRLuBoAGDiBoFqh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc3c3c3c383ff3f
Perceptual Hash:ad78877087d20fd2
Difference Hash:232b2b2b2b2b3360
Wavelet Hash:ff8181818181ff3f
Color Hash:#40bfb0

Scan History

Scan history not available

Unable to load historical scan data