Security Scan Report: www.obdecor.es

Site favicon
Submitted: Sep 15, 2026, 1:47:33 PMCompleted: Sep 15, 2026, 1:48:11 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Legit-looking Spanish renovation site on a 1-day-old domain that serves a ClickFix/EtherHiding exploit-kit campaign: CRITICAL IDS malware-exfil and exploit-kit alerts plus multiple malware Indicators of Compromise. Do not interact.

Risk Factors
Domain registered 1 day ago (CRITICAL age category)
Exploit-kit check-in and EtherHiding malware-exfiltration IDS alerts
Multiple content-malware Indicators of Compromise on resources loaded by the page
ClickFix-style fake verification page instructing users to run terminal commands
EtherHiding blockchain smart-contract payload retrieval
Domain age information unavailable

Details

Page Title

Reformas, decoración y construcción en Murcia - Obdecor

Scan Type

public

Domain Name Analysis

Within the Spanish country-code top-level domain (.es), 'www.obdecor.es' is registered with subdomain 'www'. The core label 'obdecor' covers 7 characters with three vowels and 4 consonants. Splitting it apart reveals 2 words: ob, decor. Expect 3.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.obdecor.es

Page Load Overview

12.75s
Total Load Time
2.6 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:2,555 chars
Detector Agreement:100%

Website Classification

Primary Category

blog personal website90% confidence
Type: spa
Method: ml+structural

All Detected Categories

blog personal website
90%
documentation technical
88%
corporate business
81%
real estate property
49%
government public service
48%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
3104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3162.210.96.124United States
AS14555LiquidNet US LLC
3150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
6318--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13044C84FEB3633F0724397D4BCEAE3B4D19CD213A64204D6BD60E6156B8326B4A7216D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:a6hDS27IBJXSQ3fucSH54skc2XVeIUjnEgIPXxxA4kQG:lDS27IBJXSQ3fucSH54skc2XVeIUjnEQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:277806:gEzJJgyjIDAgA76FAKeYgYBEZIQDQIzDAFACJggMQgDygnBAEFBENFQsA0ziiBtAAQEpAKQDKoCQh0sIRkVBYEZcCIFeI4ER

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Scan History

Scan history not available

Unable to load historical scan data