Security Scan Report: kingdomsgallerytour.com

Site favicon
Submitted: Sep 16, 2026, 5:47:31 AMCompleted: Sep 16, 2026, 5:47:59 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Content looks like a legitimate Bhutan travel agency, but IDS detects EtherHiding exfiltration traffic to a blockchain RPC domain and the page loads the malicious 'iclickfix' resource xaz2.com. Likely a compromised site served with hidden malware.

Risk Factors
EtherHiding malware exfiltration traffic detected by IDS on this page
Malicious third-party script resource (xaz2.com / iclickfix) loaded cross-origin
Blockchain RPC endpoint contacted from a non-Web3 travel site (obfuscated C2 pattern)
Primary domain flagged in threat-intel as a RAT
Crypto API usage without any legitimate cryptographic purpose on the page
Domain age information unavailable

Details

Page Title

Kingdom's Gallery Tours

Scan Type

public

Domain Name Analysis

The domain 'kingdomsgallerytour.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Its registrable label 'kingdomsgallerytour' stretches across 19 characters containing six vowels alongside 13 consonants. Splitting it apart reveals 3 words: kingdoms, gallery, tour. Median word length is 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kingdomsgallerytour.com

Page Load Overview

7.11s
Total Load Time
11.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:4,986 chars
Detector Agreement:100%

Website Classification

Primary Category

travel tourism94% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

travel tourism
94%
government public service
87%
adult content
51%
news media journalism
36%
blog personal website
35%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5198.23.51.25United States
AS14555LiquidNet US LLC
5104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.14.95Google · CDNUnited States
AS15169Google LLC
5104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.13.94Google · CDNUnited States
AS15169Google LLC
5104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
479--

Detected Technologies9

WordPressv7.0.2
100%
JQueryv3.7.1
100%
Bootstrapv5.3.2
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A532F7B1839629D46E6CEA01BBF7B97C0646A83B143379D7C10F2D8D287A4DB9045CA3

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:VPG9clXbDN6BMD+gkdJfVzf4sJ2HQn/xE6oAi5a8zlvg/dP/xB/nkWHHDZUs:Ve9c9fNwMKDfNQ62Ho/xE6x4aUg/5j/F

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11384:oAHIQUQDpHRiYGAASyQQzAW5BQFICmWFKCBj4AAEmUFIw8QhHhR8JQTAgQAAUOxAAA9YgaRJDQEDEIKIhij8xMDiCIdIIIgi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffff00c000000001
Perceptual Hash:c0d687c0aec92f7a
Difference Hash:c8c401819191d167
Wavelet Hash:fffffff840400001
Color Hash:#40bfb0

Scan History

Scan history not available

Unable to load historical scan data