Security Scan Report: elearning.ge4youth.eu

Site favicon
Submitted: Sep 14, 2026, 1:47:29 PMCompleted: Sep 14, 2026, 1:48:14 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 84%

8
Risk Score

Legitimate EU e-learning site appears COMPROMISED: 5 critical EtherHiding malware IDS alerts, a blockchain RPC connection, and an exploit-kit-flagged external script (ultraspeed.pro) mean visitors risk malware exposure. Avoid interaction and report.

Risk Factors
CRITICAL IDS alerts indicating malware (EtherHiding exfiltration) on page traffic
Blockchain RPC connection (base.drpc.org) typical of EtherHiding/drainer infrastructure
Exploit-kit-flagged third-party script (ultraspeed.pro) loaded by the page
Malware Indicator of Compromise match on the primary domain
Malicious JavaScript/exploit kit activity is independent of the site's benign e-learning content
Domain age information unavailable

Details

Page Title

All Courses - GE4YOUTH

Scan Type

public

Domain Name Analysis

The domain name 'elearning.ge4youth.eu' uses the .eu country-code top-level domain; it also runs on subdomain 'elearning'. The registrable portion 'ge4youth' spans 8 characters holding three vowels versus four consonants; bonus characters include 1 digit. Word splitting yields three words: ge, 4, youth. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://elearning.ge4youth.eu

Page Load Overview

4.96s
Total Load Time
1.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:839 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: spa
Method: structural

All Detected Categories

No categories detected

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13142.251.13.95Google · CDNUnited States
AS15169Google LLC
7109.95.158.146Poland
AS48896dhosting.pl Sp. z o.o.
7142.251.110.97Google · CDNUnited States
AS15169Google LLC
7104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.21.6.137Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.20.94Google · CDNUnited States
AS15169Google LLC
7172.67.154.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7216.239.34.36Google · CDNUnited States
AS15169Google LLC
699--

Detected Technologies12

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12993C89F97B332B572078725BDD9733492ACC1139A0209E67CB1E6248BC67A701FB15E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:yfgmrjooZ0WDXy0a3sI9ZdypaTGrVvlP92wAPub4kWfW:61r0oZPXnIVypPr9aw8ub4kWfW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:95568:YhFjH2SjIoyaESEhixKDwhmjAhCHBKSkoxDQBqdAGJB/HB4AlLAgT04L0FEkATgVAEghCAyBitYCTp/ISMA4JSoCQiYtIgcz

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:b9bf9f8f9fffdd9f
Perceptual Hash:bc47c3c33c1e3cc2
Difference Hash:6369313434343934
Wavelet Hash:98849c8e9e9f858f
Color Hash:#783a63

Other Hashes

Crop Resistant:6369313434343934

Scan History

Scan history not available

Unable to load historical scan data