Security Scan Report: www.efestotrainingclub.it

Site favicon
Submitted: Sep 15, 2026, 7:47:48 AMCompleted: Sep 15, 2026, 7:49:05 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Legitimate Italian gym (efestotrainingclub.it) is compromised and serving a ClearFake/EtherHiding malware payload — flagged by threat intel and 10 critical IDS alerts. Do not interact.

Risk Factors
Legitimate Italian business site appears compromised and is serving a ClearFake/EtherHiding malware payload to visitors
Malicious scripts loaded from attributed exploit-kit infrastructure (ultraspeed.pro, aleverifocation.beer, 178.16.52.101)
Network IDS detected malware exfiltration (EtherHiding) and exploit-kit check-in traffic
Use of dynamic code execution (eval/Function) consistent with injected dropper
Domain age information unavailable

Details

Page Title

Main Home - Efesto Training Clubsecondary capture

Scan Type

public

Domain Name Analysis

The domain name 'www.efestotrainingclub.it' uses the Italian country-code top-level domain (.it) and includes subdomain 'www'. The second-level label 'efestotrainingclub' is 18 characters long split between 7 vowels and 11 consonants. Tokenizing the label suggests five words: e, fes, to, training, club. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.efestotrainingclub.it

Page Load Overview

42.79s
Total Load Time
2.7 MB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:it-IT
Text Length:506 chars
Detector Agreement:50%

Website Classification

Primary Category

corporate35% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate
35%
government public service
25%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1789.46.105.69Arezzo, Tuscany, Italy
AS31034Aruba S.p.A.
10142.251.13.95Google · CDNUnited States
AS15169Google LLC
10104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10104.18.40.153Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10192.178.183.94Google · CDNUnited States
AS15169Google LLC
10172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10172.67.154.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10172.64.147.103Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
11711--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F0E2D833A0595036776FEBEDD097732CE1A96147DB4063A5B0FC10684AF4AF620FBA18

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:cmrjooZ0WDXy0a3E2KAlWDZdypa9pOcjhk0KDVfW:pr0oZPXH2JYypJcjhk0KDVfW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31991:LoaJQiACcsBX6GVFBnCFgqpoUEoxYJggEAJYMkANBBoEkAAI2AGTwSD4h8AwhHUDEeXShXAQIlUsGgREBOCwuvBbbgxgLyTE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018000c2e0e0c00
Perceptual Hash:9a6c6c92676d3266
Difference Hash:313133d9d8d81931
Wavelet Hash:1919193f7f2f0f01
Color Hash:#d279c3

Scan History

Scan history not available

Unable to load historical scan data