Security Scan Report: junge-sinfonie-berlin.de

Site favicon
Submitted: Sep 15, 2026, 8:47:36 AMCompleted: Sep 15, 2026, 8:48:04 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

9
Risk Score

Legitimate Berlin youth orchestra site appears compromised with ClearFake/EtherHiding malware: critical IDS exfil alerts, exploit-kit check-in and a multi-feed malicious script (ultraspeed.pro) loaded by the page. Do not browse.

Risk Factors
Content-malware indicator (ClearFake) on the primary domain
Multi-feed confirmed malicious third-party script (ultraspeed.pro)
Multiple CRITICAL network IDS alerts for EtherHiding exfiltration and exploit-kit check-in
Obfuscated/blockchain-based command-and-control behavior (EtherHiding)
Domain registration data shows an extremely recent registration date
Domain age information unavailable

Details

Page Title

Junge Sinfonie Berlin – Jung, begeistert, professionell und engagiert

Scan Type

public

Domain Name Analysis

Domain 'junge-sinfonie-berlin.de' uses the German country-code top-level domain (.de) while skipping any subdomain. The core label 'junge-sinfonie-berlin' covers 21 characters with eight vowels and eleven consonants, along with two hyphens. It segments into 5 words: junge, s, info, nie, berlin. Average segment length settles at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://junge-sinfonie-berlin.de

Page Load Overview

3.45s
Total Load Time
2.8 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:2,384 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service41% confidence
Type: spa
Method: ml+structural

All Detected Categories

government public service
41%
blog personal website
31%
education learning
28%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13213.133.104.76Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
2185.111.111.154Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
2142.250.154.95Google · CDNUnited States
AS15169Google LLC
2104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.21.6.137Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2185.111.111.157Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
2188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.154.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3914--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CE22C3DBA7DC17ADAA5C8DDE6250623770B2D0AD3D392355EAE7D7076876C207830930

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:di/bEOvA+0qpt+easa2wEkn2qmd8Ktg1mB9OHhcj8:zQf06NwEFpUHh5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10901:aBESSYGSKmBFJBDBiOgAJjWJQzU1sAFAw1gCCigeACikWqmNQQIODUAGLAACFEIUCIRIgobQotA2pIMiLEVBisMwglXQEyy6

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:870f0f0f0f0f0f0f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#864d2d

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data