Security Scan Report: elinfame.com

Site favicon
Submitted: Sep 20, 2026, 7:47:26 PMCompleted: Sep 20, 2026, 7:47:49 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Compromised WordPress poetry blog serving EtherHiding/ClearFake-style malware: five critical EtherHiding exfil IDS alerts, blockchain C2/RPC traffic, and a loaded exploit-kit host. No phishing forms, but avoid the site.

Risk Factors (5)
CRITICAL EtherHiding exfiltration IDS alerts tied to blockchain smart-contract C2
Compromised WordPress blog (self-branded poetry site) serving injected malicious script
Loaded resource from a host flagged as a ClearFake exploit kit
Primary domain itself reported as a malware loader
Multiple blockchain RPC calls and on-chain getDomain() contract queries
Domain age information unavailable

Details

Page Title

EL INFAME ESCRITOR – My WordPress Blog

Scan Type

public

Domain Name Analysis

You're looking at domain 'elinfame.com' on the commercial generic top-level domain (.com) while skipping any subdomain. The registrable portion 'elinfame' spans 8 characters containing 4 vowels alongside four consonants. It segments into 2 words: elin, fame. Median word length is four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://elinfame.com

Page Load Overview

5.64s
Total Load Time
481 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:1,118 chars
Detector Agreement:50%

Website Classification

Primary Category

adult content58% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

adult content
58%
blog personal website
38%
gambling betting
31%
news media journalism
30%
entertainment media
26%

Detected Features

Search
Articles
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11162.241.61.68Vinhedo, São Paulo, Brazil
AS31898Oracle Corporation
3104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
4111--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T190F224725361036977CC4BE48094321E94F4EA07F5213769FBE368EEFC199E704BA61A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:HJunOETArlGtmL8eD+RTKJunOETArlGtmL8eD+RTdjjOHmFb43+xZdSZUaAZkWRI:HETZTKETZTdXOHgZdypG6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:34764:BHCJQASaosJyZAsIsgpQmB4UJpQEEFiVQajDZEYIcoQP5QkAAGjYRCDGCYBUwkXTOQ0CAwQvQnnpEJEYPBWFJEAEYHATICA9

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefe7e3e00001000
Perceptual Hash:c6d1cc6639cc9b64
Difference Hash:c4cccc680b4c6509
Wavelet Hash:fffffefe00003000
Color Hash:#2dd28d

Other Hashes

Crop Resistant:c4cccc680b4c6509

Scan History

Scan history not available

Unable to load historical scan data