Security Scan Report: bmst-greiderer.at

Redirected to:
https://www.bmst-greiderer.at/
Site favicon
Submitted: Sep 17, 2026, 2:47:29 PMCompleted: Sep 17, 2026, 2:47:50 PMpubliccompleted

This website contacted 4 IPs in 2 countries across 5 domains to perform 16 HTTP transactions. The main domain is bmst-greiderer.at and was registered 1 month ago.

Submitted URL: https://bmst-greiderer.at

Effective URL:

https://www.bmst-greiderer.at/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate Austrian construction-management site apparently compromised: CRITICAL IDS EtherHiding malware alert, blockchain RPC calls, and a malware-flagged external domain (xaz2.com) loaded. Avoid; report for cleanup.

Risk Factors (4)
EtherHiding malware exfiltration traffic detected at the network level
Compromised-looking legitimate business site loading a malware-flagged third-party domain (xaz2.com)
Blockchain RPC (Sepolia testnet) endpoint invoked from the page, a known ClearFake/EtherHiding delivery pattern
Threat-intel malware report against the primary domain
Domain age information unavailable

Details

Page Title

Baumanagement Greiderer GmbH – Engagement und Erfahrung = Ihre Zufriedenheit

Scan Type

public

Domain Name Analysis

The domain name 'bmst-greiderer.at' uses the Austrian country-code top-level domain (.at) and has no subdomain. The core label 'bmst-greiderer' covers 14 characters with four vowels and 9 consonants; it also includes 1 hyphen. It segments into 4 words: bm, st, greider, er. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bmst-greiderer.at

Page Load Overview

1.74s
Total Load Time
384 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:294 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business86% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
86%
government public service
55%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4185.198.232.24Austria
AS208689helloly GmbH
4104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D1159F72027796B0760D296F812BA08C20B905FCDC77D86EA95011F89F4EC606E29C6

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hTYVArOvcMjKwtgKwthebG5dRKwtANwt/OVoEtnVG:xqIXwVwjUwiw9T

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:878:AIAACAAAAAQAAAAAAICgACCAAAAAAAAAAACAAAQAAAQIAAAIAAAAAAgAACAAAAAAAAAAAAAAAAAAARgAAAAIAAAAAAAAQQEA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff3f1f0e0000
Perceptual Hash:9fc4601f8e63f14c
Difference Hash:0686006a745acb0d
Wavelet Hash:e3ffff3f1f000000
Color Hash:#bc79d2

Scan History

Scan history not available

Unable to load historical scan data