Security Scan Report: fenix.net.ua

Site favicon
Submitted: Oct 7, 2026, 11:28:16 AMCompleted: Oct 7, 2026, 11:29:01 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate-looking 7-year-old Ukrainian furniture-hardware shop, but the page loads blockchain-RPC scripts and network IDS logged critical EtherHiding/ClickFix malware — likely compromised; do not interact or connect a wallet.

Risk Factors (4)
Critical IDS malware alerts (EtherHiding exfiltration, ClickFix domain) on a page whose own content has no reason to touch blockchain RPC nodes
Cross-origin connections to Polygon RPC endpoints embedded in the live page (wallet-drainer/EtherHiding pattern)
External resource flareua.live flagged as fakeapp malware by threat intelligence
WordPress contact form (name/email/message) present, indicating an injectable CMS surface
Domain age information unavailable

Details

Page Title

Уся меблева фурнітура тут! Інтернет-магазин Fenix Харків.

Scan Type

public

Domain Name Analysis

The domain 'fenix.net.ua' uses the Ukrainian country-code top-level domain (.net.ua). The second-level label 'fenix' is 5 characters long with 2 vowels and three consonants. Word splitting yields 2 words: f, enix. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://fenix.net.ua/uk/golovna/

Page Load Overview

8.83s
Total Load Time
2.4 MB
Total Size

Language Analysis

Primary Language

🇺🇦Ukrainian
Code: uk
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:uk
Text Length:4,807 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11109.94.209.214Tallinn, Harjumaa, Estonia
AS202376Arvid Logicum OU
1045.91.130.36Ukraine
AS205722Binotel LLC
10172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10172.66.146.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1035.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
10142.251.14.95Google · CDNUnited States
AS15169Google LLC
10142.251.14.94Google · CDNUnited States
AS15169Google LLC
10104.20.46.180Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
818--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B7143AF3D178147903536AAA6014B28CFE579034DB810AE9B3BCE66CD7C1FA8677261D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:INNIMGV1nAMQADAn9AvD0SS9GvYlffrC8aKGw+AsfY3bMDMILwTnJ:INvWMWpv6rJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:202369:W8miGJG7ASAZSIEWSAKgEIbCEkYyYmDpaHgYvQEYGiCUEgIAmBQAlXpNQQF8sAEbLSYAECRABaYAJDAqRwNQaJYaWRAERBEM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fff8909898edf8f0
Perceptual Hash:ce9da1b35294a5a5
Difference Hash:2a513230301995a5
Wavelet Hash:fff89a989080f8f0
Color Hash:#e06c6c

Scan History

Scan history not available

Unable to load historical scan data