Security Scan Report: pal-uk.com

Site favicon
Submitted: Sep 22, 2026, 3:47:26 PMCompleted: Sep 22, 2026, 3:47:53 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Established hand-sanitiser business whose page shows a CRITICAL malware/exfiltration IDS alert (EtherHiding), a blockchain RPC sink, and a third-party malware-tagged domain loaded — signs of compromise serving malware.

Risk Factors (5)
CRITICAL Suricata IDS malware/exfiltration alert (ET MALWARE EtherHiding Exfil M2)
External malware-tagged domain xaz2.com loaded as a page resource
Primary domain reported in threat intel as 'unknown rat' malware
Blockchain RPC connection combined with Crypto API usage on a non-crypto business site
Malware distribution via compromised legitimate site (ClearFake/EtherHiding pattern)
Domain age information unavailable

Details

Page Title

PAL-UK | Practical Aerosols & Liquids

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'pal-uk.com' is registered. Its registrable label 'pal-uk' stretches across 6 characters containing two vowels alongside three consonants, plus one hyphen. Word splitting yields 2 words: pal, uk. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pal-uk.com

Page Load Overview

6.56s
Total Load Time
6.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,077 chars
Detector Agreement:75%

Website Classification

Primary Category

healthcare medical79% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
79%
corporate business
60%
government public service
60%
e-commerce shopping
57%
documentation technical
47%

Detected Features

Search
Articles
Products

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14172.67.145.227Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12142.251.20.95Google · CDNUnited States
AS15169Google LLC
12104.21.28.114Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12104.26.13.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12142.251.14.94Google · CDNUnited States
AS15169Google LLC
746--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BD24B7DFDB713774339BD2A8BCD632B4B99D8027D64118A27C60969853C2297137B28F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:fiC79ypFrZDS27esS4ZAe4kQYnjlDwIrdczEF7aC6S6:n7YlDS27l4kQYnjlDwIrdczEYC6Z

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:223968:ZwABSQ4ACC7RlUJgYirtUN0BKNzBYAAuKFgQioxQg0NAjNxUQB9BIIJjQqoAbUjdDIDAiyAFIsYAIhIOCDBsgyquwMRUyqG7

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0101010103ffff
Perceptual Hash:a92cd692d1ed24d6
Difference Hash:3fe7e7d3db7f69ca
Wavelet Hash:ff0101010703ffff
Color Hash:#9653ac

Scan History

Scan history not available

Unable to load historical scan data