Security Scan Report: gaviticonsulting.com

Site favicon
Submitted: Sep 17, 2026, 8:47:28 AMCompleted: Sep 17, 2026, 8:48:05 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Legitimate-looking consulting domain appears compromised: it loads multiple corroborated malicious domains and triggers CRITICAL exploit-kit and EtherHiding malware IDS alerts plus injected darknet spam. Avoid.

Risk Factors
CRITICAL exploit-kit ('ErrTraffic Beer Cluster') and malware (EtherHiding exfil) IDS alerts triggered by the page
Multiple multi-source malicious third-party domains loaded by the page (mioiooo.icu, cloudflare-check.net, aleverifocation.beer, clickzona.net)
Primary domain listed as 'unknown loader (malware)' in threat intelligence
Blockchain RPC / Ethereum contract interactions consistent with EtherHiding malware delivery
Injected darknet marketplace spam content on an otherwise legitimately-branded site
Obfuscated/dynamically generated JavaScript (6 Function() constructor calls)
Domain age information unavailable

Details

Page Title

Gaviti Consulting S.A.S

Scan Type

public

Domain Name Analysis

Domain 'gaviticonsulting.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Count 16 characters in 'gaviticonsulting' with 6 vowels and 10 consonants. Word splitting yields three words: ga, viti, consulting. The median word length lands at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gaviticonsulting.com

Page Load Overview

17.63s
Total Load Time
1.8 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:6,485 chars
Detector Agreement:50%

Website Classification

Primary Category

corporate70% confidence
Type: dynamic
Method: structural

All Detected Categories

corporate
70%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12162.241.61.248Vinhedo, São Paulo, Brazil
AS31898Oracle Corporation
3104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.1.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3104.18.67.220Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.0.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
358.64.137.69Hong Kong
AS17444HKBN Enterprise Solutions Limited
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4512--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T124427A8303B41AAC528049D9805D3A6255F6D1BB2C1D6BDCBDEA6E17FF3FF145606A30

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:jxVTIZRiiuilYIFhifSWNlA73ES/SyuO/2JweTXl6nKUTsOXA2EvZBIhKEUZD+rw:j3TjSES/S/xjl6nlAjMKEmQv9wYwTC09

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12250:C4IG4EGoERGOg6GQPKAgBkSAahk9otME4ADGyoJgsBAOkChJRcROwFTCIyIyUkAE0AUkJBgjhgQWCECaXhomFEUBADlAQQS4

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:8b0b2b2b2b6b6a6a
Difference Hash:41c0000000000000
Wavelet Hash:00ffffff00000000
Color Hash:#862d58

Other Hashes

Crop Resistant:41c0000000000000

Scan History

Scan history not available

Unable to load historical scan data