Security Scan Report: taotui.cn

Site favicon
Submitted: Sep 20, 2026, 3:47:29 PMCompleted: Sep 20, 2026, 3:47:56 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Critical malware IDS alert and multi-source malware Indicators of Compromise on loaded domain xaz2.com indicate this site is compromised or maliciously serving malware/EtherHiding exfiltration. Avoid interaction.

Risk Factors
Critical network IDS alert: ET MALWARE EtherHiding Exfil M2
Page loads xaz2.com, a domain corroborated as malware (iclickfix) by multiple threat feeds
Primary domain taotui.cn has a malware loader report (single-source, unverified)
Blockchain RPC connection to rpc.sepolia.ethpandaops.io detected, matching EtherHiding malware behavior
Domain age information unavailable

Details

Page Title

淘推官网大全 – 只收录真正的官方网站

Scan Type

public

Domain Name Analysis

The domain name 'taotui.cn' uses the Chinese country-code top-level domain (.cn). The core label 'taotui' covers 6 characters containing four vowels alongside 2 consonants. Tokenizing the label suggests two words: tao, tui. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://taotui.cn

Page Load Overview

4.62s
Total Load Time
379 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-Hans
Text Length:2,008 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software57% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
57%
adult content
28%
documentation technical
26%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
843.133.209.17Tokyo, Tokyo, Japan
AS132203Tencent Building, Kejizhongyi Avenue
5125.74.108.43China
AS141998China Telecom
5117.187.133.32China
AS138407The Internet Data Center of Guizhou Mobile Communication Company Limited
5104.26.12.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
543.159.107.113Singapore
336--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10ED2F932D2A440E13E1DC76CB2F2B23C6558AA15DA0367A7F0BD3058596D9FB00E7A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:q9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyfVyWmFV4r/ZdSZUaAfkWxN:q9i5Q62I/xE6x4g5bn/gIWNZdyp6j

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28435:aKCmCkoFEbQQYRKKSJAAEJBIP+FBPsiDgLCMAiQqaDIgB3MYJwRAHVRTCCAq4ABAV2rAgCYnwtBASRWUKCpoIUIMGBEiASAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7c3c3c1fffffff7
Perceptual Hash:b030c5cb6633cccf
Difference Hash:9d9d959d95e290a4
Wavelet Hash:4040c0c1ddfdfdf1
Color Hash:#d2797e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data