Security Scan Report: driftwoodresortmn.com

Site favicon
Submitted: Sep 23, 2026, 1:18:47 PMCompleted: Sep 23, 2026, 1:21:42 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Established Minnesota cabin-rental site appears compromised: critical IDS malware/EtherHiding alerts, malicious third-party domains, blockchain RPC calls, and injected casino/steroid spam. Avoid interacting.

Risk Factors
Malware/ClickFix (AMOS loader) and EtherHiding exfiltration alerts from the IDS
Malicious third-party script/font domains loaded (clearfake kit infrastructure)
Blockchain RPC connections indicating EtherHiding / wallet-drainer technique
Injected spam and illegal-product (steroids, casino) content on legitimately-hosted page
Primary domain appears compromised and flagged for malware
Domain age information unavailable

Details

Page Title

Drift wood – Cabin Rentals Minnesota | Driftwood Resort

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'driftwoodresortmn.com' is registered with no subdomain. The registrable portion 'driftwoodresortmn' spans 17 characters split between five vowels and 12 consonants. Word splitting yields three words: driftwood, resort, mn. The median word length lands at six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://driftwoodresortmn.com

Page Load Overview

75.13s
Total Load Time
6.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:6,975 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media100% confidence
Type: spa
Method: ml+structural

All Detected Categories

entertainment media
100%
gambling betting
99%
technology software
97%
download file sharing
91%
government public service
90%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12199.192.27.115United States
AS22612Namecheap, Inc.
5142.251.13.95Google · CDNUnited States
AS15169Google LLC
5138.124.60.214Switzerland
AS203273NetCrafters OU
5142.250.154.95Google · CDNUnited States
AS15169Google LLC
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5142.250.154.94Google · CDNUnited States
AS15169Google LLC
5172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
5104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8716--

Detected Technologies6

WordPressv7.1.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12482B772F0A55156BF5E9BEDC1D27328F568A601CA02E7BA70F4305486A8EF700F762D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:PFRWfSkE6UNzvab25rqwRXdSZsTaAh369K3h1TNslQCfEGHRmy4kW5SR9lp6DN:NRy4RNjab25r/ZdSZUaAhDkW86DN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18133:IBA4gZAwBmAWG1BUCMGAIBXW0EORxaAgRwASEI2oDAAATCEB1qIgTEmbiNDgFApmgaEgAhAcAEhAVi5hQAzBLiagqBKCAVEh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff9fffff0307070f
Perceptual Hash:9cfc9c03e3c38347
Difference Hash:30343041fffffefe
Wavelet Hash:df9fdf8b00030707
Color Hash:#2dd28d

Scan History

Scan history not available

Unable to load historical scan data