Security Scan Report: andrewsenterprises.org

Site favicon
Submitted: Sep 17, 2026, 2:47:32 AMCompleted: Sep 17, 2026, 2:48:06 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Compromised credit-repair blog serving a ClearFake/EtherHiding exploit kit — 14 CRITICAL IDS hits, blockchain-RPC payload delivery, and a fake Cloudflare 'verify' prompt pushing manual command execution. Do not click or follow any prompts.

Risk Factors (6)
Critical IDS malware/exploit-kit signatures (EtherHiding exfiltration, ErrTraffic check-in) indicate active malicious script delivery
Primary domain reported as ClearFake malware infrastructure
Multiple third-party resources loaded from domains flagged as exploit-kit / wp-inject infrastructure
Blockchain RPC abuse (EtherHiding) used to fetch malicious payloads immutably
Fake Cloudflare verification prompt directing users to execute manual commands (ClickFix)
Heavy Form/Functions constructor usage (8 calls) consistent with obfuscated injected code
Domain age information unavailable

Details

Page Title

Andrews Enterprises – I fix credit with wisdom

Scan Type

public

Domain Name Analysis

The domain name 'andrewsenterprises.org' uses the non-profit oriented generic top-level domain (.org) while skipping any subdomain. Its registrable label 'andrewsenterprises' stretches across 18 characters with six vowels and 12 consonants. Word splitting yields 2 words: andrews, enterprises. Average segment length settles at 9 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://andrewsenterprises.org

Page Load Overview

11.25s
Total Load Time
241 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,024 chars
Detector Agreement:67%

Website Classification

Primary Category

blog personal website98% confidence
Type: spa
Method: ml+structural

All Detected Categories

blog personal website
98%
documentation technical
97%
government public service
96%
cryptocurrency blockchain
94%
corporate business
92%

Detected Features

Search
Comments

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4212--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19DC2B73292F888E17A1E877C85947214AC94EB10DF0767D5F0B5E068899DEFB04EB71D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:NXOS8rG2W+WmF/c30r4r/ZdSZUaAfkWZN:pSjW+WKck8Zdyp67

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:25955:ch4IMAMQi0GRCBWEAS3AB4EgZNc19dggEQZFxCLFdBiq8mMQFpZKyJIAFtQWVQEANxIXWCoHVeQcAWQHZRaRAEEoCCNYgCUA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bfe7fdff00ffffff
Perceptual Hash:ea7ab63614cdc84a
Difference Hash:2c0d230201000000
Wavelet Hash:000099f900fefffe
Color Hash:#e0776c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data