Security Scan Report: mobel.co.za

Site favicon
Submitted: Sep 14, 2026, 5:47:51 PMCompleted: Sep 14, 2026, 5:48:26 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate 12-year-old joinery site appears compromised: injected gambling/pharma SEO spam, JS POSTs to malware domain datadock.info, and CRITICAL IDS alerts for EtherHiding exfiltration and JS redirect exploits.

Risk Factors
Injected SEO spam content (gambling, casino, pharmaceutical) on a legitimate joinery website
Cross-origin JavaScript POST to a domain reported as WordPress malware injection (datadock.info)
Multiple multi-source Indicators of Compromise on resources loaded by the page
CRITICAL IDS alerts indicating EtherHiding exfiltration and multi-stage JavaScript redirect/exploit-kit activity
Abnormal outbound blockchain RPC connections consistent with compromised-site dead-drop techniques
Domain age information unavailable

Details

Page Title

mobel – CUSTOM JOINERY

Scan Type

public

Domain Name Analysis

Within the South African country-code top-level domain (.co.za), 'mobel.co.za' is registered and has no subdomain. Its registrable label 'mobel' stretches across 5 characters with two vowels and 3 consonants. It segments into two words: mob, el. Median word length is 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mobel.co.za

Page Load Overview

14.73s
Total Load Time
2.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:18,360 chars
Detector Agreement:25%

Website Classification

Primary Category

gambling betting41% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
41%
documentation technical
29%
entertainment media
26%
news/blog
20%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13129.232.138.143Johannesburg, Gauteng, South Africa
AS37153Xneelo (Pty) Ltd
474.125.29.95Google · CDNUnited States
AS15169Google LLC
4178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
4152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
4104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4142.251.14.94Google · CDNUnited States
AS15169Google LLC
4162.244.35.233Santa Clara, California, United States
AS14576Hosting Solution Ltd.
4142.251.20.94Google · CDNUnited States
AS15169Google LLC
4910--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BC036625935888E2359FCB298186F31CE659BEC0D98D1767F0B5E22058CD2B924B7F1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Iht2D2WdNJ6Ih7BXkWP+/AylU0b0iBza4r/ZdSZUaAhHkWON:stNWjH+b0A1Zdypa9G

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:40277:AIo4rEpCAYygCACCRgSYscSBbnARWBYSYVxEaIEpA5AAMRCjACEcqAHBAG/jSAHwiawIAFcoBEEkYViFBAASRREEBo1JMCOo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffff00000000
Perceptual Hash:badc3c1c3c9c54c5
Difference Hash:3020000101010101
Wavelet Hash:ffffffff00000000
Color Hash:#53ac6c

Other Hashes

Crop Resistant:3020000101010101

Scan History

Scan history not available

Unable to load historical scan data