Security Scan Report: mghirealty.com

Site favicon
Submitted: Sep 16, 2026, 8:47:29 PMCompleted: Sep 16, 2026, 8:48:19 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Compromised WordPress realty site serving EtherHiding/ClearFake malware via blockchain C2 (polygon.drpc.org) and ErrTraffic exploit-kit check-ins, with injected gambling SEO spam; flagged malicious by two independent feeds.

Risk Factors (5)
EtherHiding/ClearFake malware infrastructure (critically alerted by IDS)
ErrTraffic exploit-kit 'Beer Cluster' check-in traffic to flagged host aleverifocation.beer
Blockchain RPC (polygon.drpc.org) domain resolution via getDomain() used as malicious content sink
Primary domain mghirealty.com matched as malware in two independent threat feeds, plus a content-malware URL Indicator of Compromise
WordPress install compromised with injected off-topic gambling SEO spam (Turkish casino keywords unrelated to real estate)
Domain age information unavailable

Details

Page Title

My Global Hub International Realty – Real Estate with Global Vision

Scan Type

public

Domain Name Analysis

Domain 'mghirealty.com' uses the commercial generic top-level domain (.com) without a subdomain. The core label 'mghirealty' covers 10 characters with 3 vowels and 7 consonants. Breaking it apart gives 3 words: mg, hi, realty. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mghirealty.com

Page Load Overview

22.19s
Total Load Time
21.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:26,740 chars
Detector Agreement:25%

Website Classification

Primary Category

gambling betting99% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
99%
entertainment media
97%
real estate property
89%
government public service
80%
adult content
65%

Detected Features

Login Form
Comments

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2092.113.23.163Frankfurt am Main, Hesse, Germany
AS47583Hostinger International Limited
1713.226.244.31Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
17142.251.13.95Google · CDNUnited States
AS15169Google LLC
1713.226.244.128Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1713.226.244.67Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1713.226.244.37Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
17142.250.154.95Google · CDNUnited States
AS15169Google LLC
17104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
17142.251.13.94Google · CDNUnited States
AS15169Google LLC
17178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
19011--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DB4185332614203DA27346D278E5B79C774AC517630194B4ACF226CC92DDB9545F97CE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:Tm0ZiXTNaNOZVWmjEuZBvVRRcUl/O03CttJwDBRZAdD:TmImZfjjhdO0yttqDbuZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2319:AAAAAAAQCAQQAEBAAAAiAAAAEEgABDAAICCAEUMAAECIAABAiIEAAQAAQIABACAAQQBAwAAQAQBAAAgAIAAIIAAAgAEAQAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7c3ffffff
Perceptual Hash:b38ccc3333cccc33
Difference Hash:0000000c0c000000
Wavelet Hash:f0f0f8e0c0f8cccc
Color Hash:#53ac6b

Other Hashes

Crop Resistant:0000000c0c000000

Scan History

Scan history not available

Unable to load historical scan data