Security Scan Report: redsmart.online

Site favicon
Submitted: Sep 13, 2026, 7:47:35 PMCompleted: Sep 13, 2026, 7:48:08 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Compromised domain serving a ClickFix fake-CAPTCHA that tricks users into running PowerShell, plus CRITICAL EtherHiding blockchain-exfil malware alerts — do not interact.

Risk Factors
Fake reCAPTCHA verification demanding the user run PowerShell commands (ClickFix malware lure)
CRITICAL network IDS alerts for EtherHiding exfiltration (malware C2 via blockchain)
Blockchain RPC/testnet connections combined with loader behavior
Primary domain flagged as malware loader
eval()/Function() dynamic code execution
Legitimate 8-year-old Joomla/ZooTemplate site appears hijacked to serve a loader
Domain age information unavailable

Details

Page Title

INICIO - REDSMART

Scan Type

public

Domain Name Analysis

The domain name 'redsmart.online' uses the modern generic top-level domain (.online) while skipping any subdomain. The second-level label 'redsmart' is 8 characters long split between two vowels and six consonants. It segments into two words: red, smart. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://redsmart.online

Page Load Overview

10.86s
Total Load Time
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:29%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:1,557 chars
Detector Agreement:50%
Language mismatch: Declared as es but detected as en

Website Classification

Primary Category

entertainment media83% confidence
Type: spa
Method: ml+structural

All Detected Categories

entertainment media
83%
technology software
78%
adult content
67%
corporate business
67%
documentation technical
52%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
19157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
5162.241.2.34Vinhedo, São Paulo, Brazil
AS31898Oracle Corporation
5104.20.20.192Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.250.154.95Google · CDNUnited States
AS15169Google LLC
53.33.155.121Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5192.178.183.94Google · CDNUnited States
AS15169Google LLC
5142.251.154.4Google · CDNUnited States
AS15169Google LLC
53.33.196.84Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5142.215.53.55Washington, District of Columbia, United States
AS15830Equinix (EMEA) Acquisition Enterprises B.V.
552.223.48.152Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
12422--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CCE2A5B361590AA13F5D93A8C042322CA696A143D611BA7BB4FC516C0BD86FF11FB35F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:acEzK0H0lz2CMgwr/ZdSZUaAhHkW9pd41GNuez73hEKKw/R:gK3ACMNZdypa99pd5uez73hEKKw/R

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31801:iEBkhihBhtaEXYIOwmEBEMJMkAAgBUaTR04A4giBJxBB8BI2Vj0EASQ9ANPNCIwQBVJUwKMBAUKLyAxFggiJCNsEtcTCAgCE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2f2d81ffffffffff
Perceptual Hash:9f1f0f8f95e0e060
Difference Hash:75692b4000000000
Wavelet Hash:000000fe0e0e0e0e
Color Hash:#42783a

Other Hashes

Crop Resistant:75692b4000000000

Scan History

Scan history not available

Unable to load historical scan data