Security Scan Report: helixperfect.com

Site favicon
Submitted: Oct 1, 2026, 1:05:14 PMCompleted: Oct 1, 2026, 1:07:22 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 84%

9
Risk Score

Compromised consulting site loading EtherHiding blockchain-based malware (CRITICAL ET MALWARE IDS alert) with malware IoC matches on the domain and URL. Do not visit; the page appears tampered to distribute a crypto-loader.

Risk Factors (5)
EtherHiding malware exfiltration detected by network IDS (CRITICAL)
Blockchain RPC connections used to fetch/execute hidden payloads
Threat-intel malware match on the primary domain and the exact page URL
JavaScript obfuscation behavior alongside blockchain calls
Suspicious unranked third-party script host (browseid.codes) serving code
Domain age information unavailable

Details

Page Title

Helix Perfect - Shaping the future of our Energy partners –

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'helixperfect.com' is registered. Its registrable label 'helixperfect' stretches across 12 characters containing 4 vowels alongside eight consonants. Splitting it apart reveals two words: helix, perfect. The median word length lands at six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://helixperfect.com/

Page Load Overview

15.23s
Total Load Time
4.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:6,684 chars
Detector Agreement:80%

Website Classification

Primary Category

healthcare medical52% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
52%
news media journalism
49%
adult content
48%
cryptocurrency blockchain
47%
finance banking
44%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
19129.121.65.120Phoenix, Arizona, United States
AS31898Oracle Corporation
9142.250.154.97Google · CDNUnited States
AS15169Google LLC
9104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
9178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
9146.75.120.157Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
9216.239.34.36Google · CDNUnited States
AS15169Google LLC
9172.66.0.227Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10911--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DB041B7375C5182A135743CA921A370CB0CBF5ABD902D4C8B3BF41A9EBD8ED17927299

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:OO19cqDQpypl3FCjEuLez6a6QQ7ajePLgOSdq3ebezEepGUHj+N5fyUe:+qDQkX3UjEuL26a6iekvQj9j

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184689:EbHeCEIb82xB5gSGiKAIBSSUQ6VvARBJYFQZEIHASMYkQ/oAAwcEAOwAhk4JaGDQLmhjwRggAYtiFREEMgTYBAwJCJFBEQJI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9f9f9f9fbf1d0400
Perceptual Hash:9ebc71c745706217
Difference Hash:353335316b69797d
Wavelet Hash:0f9f9f1fbf1d0000
Color Hash:#936b1f

Scan History

Scan history not available

Unable to load historical scan data