Security Scan Report: fahrschule-heidisch.de

Site favicon
Submitted: Sep 20, 2026, 11:47:25 PMCompleted: Sep 20, 2026, 11:47:49 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 86%

8
Risk Score

Legitimate German driving-school site whose page has been compromised and injected with EtherHiding/ClearFake blockchain-malware scripts — CRITICAL Suricata malware alert plus multiple corroborated clearfake/RPC threat-intel hits. Do not interact.

Risk Factors (6)
CRITICAL IDS malware alert: EtherHiding exfiltration (network trojan)
Blockchain RPC connection (Polygon mainnet) consistent with EtherHiding/ClearFake wallet-drainer loaders
Multiple corroborated 'ek clearfake' threat-intel matches on resources loaded by the page (wmicconfidance.info, quiknode.pro RPC)
Primary domain flagged as a malware loader
Obfuscated inline JavaScript (encoding/decoding functions, Function() constructor) on a site whose content has no need for dynamic code generation
HIGH IDS alert: Spamhaus DROP-listed traffic
Domain age information unavailable

Details

Page Title

Fahrschule Heidisch - Deine Fahrschule in Eibau / Kottmar

Scan Type

public

Domain Name Analysis

The domain 'fahrschule-heidisch.de' uses the German country-code top-level domain (.de) while skipping any subdomain. Count 19 characters in 'fahrschule-heidisch' holding 6 vowels versus 12 consonants; it also includes one hyphen. Tokenizing the label suggests 5 words: fah, r, schule, heidi, sch. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://fahrschule-heidisch.de

Page Load Overview

4.15s
Total Load Time
823 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:2,595 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2085.13.145.45Germany
AS34788Neue Medien Muennich GmbH
18150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
18178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
18142.251.110.94Google · CDNUnited States
AS15169Google LLC
744--

Detected Technologies8

WordPressv6.9.4
100%
JQueryv3.7.1
100%
Bootstrapv1789948048
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1317319266EDCE4356707C7789AA77E39E7149146882D3E7871AD883C43CE0F502EF52A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:cN4dMb/eQ7dLWS2jXCTbyzzo2+xC8CnNDaOh6EGjRb82qZdypKtC+NjmLx:nmn7dLWbjiby5GjRb82Syp2C+Nj8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:75472:y2g3VIQqLCZACwsRUB+FYJFEyIVbwKERIBlg4EKACl1hjMAIzWjTCoA0ZAAIGhIxEBYpCKAEiobZDigARFAMgFRUKCC+SsEg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:69200c6c6000ff01
Perceptual Hash:c353bce4c399389c
Difference Hash:d1c539c9c931e121
Wavelet Hash:ff210d6d6101ff11
Color Hash:#40931f

Scan History

Scan history not available

Unable to load historical scan data