Security Scan Report: takeaway.parks-nuernberg.de

Site favicon
Submitted: Sep 13, 2026, 1:47:31 AMCompleted: Sep 13, 2026, 1:48:37 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Legitimate-looking PARKS Nürnberg takeaway site that appears compromised: 5 CRITICAL EtherHiding malware IDS alerts, a blockchain C2 connection, and a malicious third-party resource loaded. Avoid.

Risk Factors
Critical IDS malware/EtherHiding exfiltration alerts (network-level C2)
Cross-origin blockchain RPC connection used for malware delivery (EtherHiding)
Page loads a resource (ultraspeed.pro) flagged malicious by 3 independent feeds
Primary domain flagged in threat intelligence as iclickfix malware
Heavy use of dynamic Function() code generation (obfuscation)
Domain age information unavailable

Details

Page Title

Takeaway | PARKS Nürnberg – EVENTLOCATION. CAFÉ. RESTAURANT. BAR.

Scan Type

public

Domain Name Analysis

Domain 'takeaway.parks-nuernberg.de' uses the German country-code top-level domain (.de) with subdomain 'takeaway'. The second-level label 'parks-nuernberg' is 15 characters long split between four vowels and ten consonants, along with one hyphen. Word splitting yields four words: parks, nu, e, rnberg. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://takeaway.parks-nuernberg.de

Page Load Overview

41.19s
Total Load Time
3.1 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:5,758 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking29% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
29%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1081.88.34.125Germany
AS8648dogado GmbH
10104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10142.251.110.95Google · CDNUnited States
AS15169Google LLC
10142.250.154.94Google · CDNUnited States
AS15169Google LLC
10104.18.40.153Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10104.21.6.137Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10142.251.14.94Google · CDNUnited States
AS15169Google LLC
10104.18.6.168Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10104.18.7.168Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10172.64.147.103Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10010--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BF03E761F3AD1452BB4B03AC285DB6C8667C6214CD005FBAF874E274668C0BA05BFB5F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:FPmrjooZ0WDXy0a3J0gZdap66AijG0TaxglUxfW:Fer0oZPX2ap8ijGkUxfW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:40673:EBTPTgBAsBoIgBgASQBBETiQPAwcAgEcN3ECB5oMkfSQHZJU4CMC+AKQAADMSkQyNAoIgIxiRSEgnLwAwCAhFAAhAJIAAnIk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefeffffffffffff
Perceptual Hash:d5555555555515aa
Difference Hash:0000000000000000
Wavelet Hash:0e0e0e0e0e0e0e0e
Color Hash:#693a78

Other Hashes

Crop Resistant:0000000000000000

Scan History

Scan history not available

Unable to load historical scan data