Security Scan Report: realestatethedeal.com

Site favicon
Submitted: Sep 19, 2026, 1:47:29 PMCompleted: Sep 19, 2026, 1:48:07 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate-looking Albanian real-estate site that appears compromised: CRITICAL ET MALWARE EtherHiding exfiltration alerts, blockchain RPC calls and a 2-feed malware domain loaded. Treat as malicious; do not interact.

Risk Factors
CRITICAL IDS malware signatures (EtherHiding exfil) present in captured network traffic
Malware-flagged third-party domain (xaz2.com, 2 feeds) loaded by the page
Primary domain IoC: reported as unknown RAT (malware), single-source unverified
Blockchain RPC endpoints loaded on a non-web3 brochure site — anomalous and consistent with injected drainer/exfil scripts
Domain age information unavailable

Details

Page Title

The Deal Real | Estate Agency in Vlore

Scan Type

public

Domain Name Analysis

The domain name 'realestatethedeal.com' uses the commercial generic top-level domain (.com). Count 17 characters in 'realestatethedeal' holding eight vowels versus 9 consonants. Splitting it apart reveals 4 words: real, estate, the, deal. Median word length is 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://realestatethedeal.com

Page Load Overview

17.67s
Total Load Time
3.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,085 chars
Detector Agreement:100%

Website Classification

Primary Category

real estate property52% confidence
Type: spa
Method: ml+structural

All Detected Categories

real estate property
52%
corporate
35%
news/blog
20%

Detected Features

Search
OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8159.69.3.54Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
7142.251.127.95Google · CDNUnited States
AS15169Google LLC
7198.23.142.12Buffalo, New York, United States
AS36352HostPapa
7142.250.154.95Google · CDNUnited States
AS15169Google LLC
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.26.13.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.14.94Google · CDNUnited States
AS15169Google LLC
7142.251.156.119Google · CDNUnited States
AS15169Google LLC
7142.251.127.94Google · CDNUnited States
AS15169Google LLC
16924--

Detected Technologies12

WordPressv7.1.1
100%
JQueryv1.0.2
100%
Bootstrapv1.5.9
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13DD3D76772F039732BDF452D5684B90923D881E7D50C2EFEBAB79B9819CD9C103A2607

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:oiC+1nfFkhschschsmdo5kypm+sXDbYXDbYXDbO:ms64M+h

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:142315:lDAGTSuA1y0oAAGhMPgQMGBoIAQCEnDFsiZQKAACKqWfIJIBGAoFNc6JKBIEkjJQwKVBAGiaoRBpDApWgu/BMhBCAEBRMUDC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffc30326fe1f03
Perceptual Hash:a1f29cd707b36c12
Difference Hash:8c879fcfccc0ddf7
Wavelet Hash:fffb4303027c0f03
Color Hash:#ac6553

Other Hashes

Crop Resistant:8c879fcfccc0ddf7

Scan History

Scan history not available

Unable to load historical scan data