Security Scan Report: feng-shui.ua

Submitted: Sep 13, 2026, 5:48:11 AMCompleted: Sep 13, 2026, 5:49:42 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Host serves a malicious JS/C2 stager (reported as 'sliver' malware by 2 feeds); script drops and executes a remote payload as fake system binary and wipes logs. Avoid.

Risk Factors
Content-malware threat-intel match on the primary domain script, corroborated by 2 independent feeds
Payload delivery/dropper code wget-fetching an external JS as a fake system binary
Anti-forensic behaviour (history wiping, timestamp manipulation)
Domain unranked in Cisco Umbrella while serving malicious script content
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

You're looking at domain 'feng-shui.ua' on the Ukrainian country-code top-level domain (.ua). The registrable portion 'feng-shui' spans 9 characters holding three vowels versus five consonants; it also includes 1 hyphen. Tokenizing the label suggests two words: feng, shui. Median word length is four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://feng-shui.ua/b/in.js

Page Load Overview

17.67s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:48%
Script:Latin
Direction:ltr

Detection Details

Text Length:302 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software46% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
46%
cryptocurrency blockchain
44%
documentation technical
39%
finance banking
37%
healthcare medical
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
231.131.27.63Rotterdam, South Holland, Netherlands
AS56851PE Skurykhin Mukola Volodumurovuch
21--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13DF02767F068A035EE6009696BD1BD8094C68509AA32BFD4B3D49BE0F449BBAA042358

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:kxV7HdBWK4/B3dPIhR4RdidGfxj1S57h3Y:kHTz4/VdKaRdiKh1S576

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:59cbde7820812794a4f2e55b6b1ce552

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f1fffffffffffff
Perceptual Hash:8b0b0b0b1b1b3bf9
Difference Hash:f8e0000000000000
Wavelet Hash:00f0f0f0f0f0f0f0
Color Hash:#e0876c

Other Hashes

Crop Resistant:f8e0000000000000

Scan History

Scan history not available

Unable to load historical scan data