Security Scan Report: asa-gmbh-bln.de

Redirected to:
https://www.asa-gmbh-bln.de/
Site favicon
Submitted: Sep 13, 2026, 7:47:37 PMCompleted: Sep 13, 2026, 7:48:35 PMpubliccompleted

This website contacted 7 IPs in 2 countries across 7 domains to perform 53 HTTP transactions. The main domain is asa-gmbh-bln.de and was registered 2 weeks ago.

Submitted URL: https://asa-gmbh-bln.de

Effective URL:

https://www.asa-gmbh-bln.de/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate established Berlin winter-service business whose WordPress site appears compromised: CRITICAL ET MALWARE EtherHiding exfil alert, blockchain RPC beacon, and multi-source malware IoCs (xaz2.com, primary-domain RAT report).

Risk Factors
CRITICAL IDS malware alert (ET MALWARE EtherHiding Exfil M2)
Blockchain RPC connection consistent with EtherHiding payload/exfiltration
External domain xaz2.com flagged as malware by 2 independent feeds
Primary domain reported as malware/RAT by threat-intel feed (single-source)
Indicators suggest compromised legitimate WordPress site injecting malicious scripts
Domain age information unavailable

Details

Page Title

Schnee- und Abfallbeseitigung in Berlin

Scan Type

public

Domain Name Analysis

Domain 'asa-gmbh-bln.de' uses the German country-code top-level domain (.de). The registrable portion 'asa-gmbh-bln' spans 12 characters split between 2 vowels and eight consonants, along with two hyphens. Tokenizing the label suggests 5 words: as, a, gmbh, b, ln. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://asa-gmbh-bln.de

Page Load Overview

33.63s
Total Load Time
6.6 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:12,704 chars
Detector Agreement:100%

Website Classification

Primary Category

real estate property88% confidence
Type: spa
Method: ml+structural

All Detected Categories

real estate property
88%
corporate
35%
corporate business
27%
news/blog
20%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11142.251.155.119Google · CDNUnited States
AS15169Google LLC
781.169.145.148Germany
AS6724Strato GmbH
7142.251.154.119Google · CDNUnited States
AS15169Google LLC
7142.251.14.94Google · CDNUnited States
AS15169Google LLC
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.20.94Google · CDNUnited States
AS15169Google LLC
7104.26.13.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
537--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CCC21932D29184D63F5DDBA8B2F2B22C5954F61585137BA3B0FD209C5AA81F70093E2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:U9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyR3ZIpV3ZdqZUaA9nLkWYG2:U9i5Q62I/xE6x4g5bn/W3ZIjZdapeYG2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:27317:pcARN6bDqkAsEjqQoaCzbEOAgB08BIKIcpjTGBABJAIhkxoyNglRgApICTxDdmBKIaCEmEACAsKBIvxIBVmAGDbyIUdhApmC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:009d3dbd3d019101
Perceptual Hash:9a93346130cbf1cf
Difference Hash:0f29696971132337
Wavelet Hash:019dbfbdbd819901
Color Hash:#1f9331

Scan History

Scan history not available

Unable to load historical scan data