Security Scan Report: shoetimewholesale.com

Redirected to:
http://www.shoetimewholesale.com/
Site favicon
Submitted: Sep 17, 2026, 4:47:42 AMCompleted: Sep 17, 2026, 4:48:38 AMpubliccompleted

This website contacted 20 IPs in 1 country across 21 domains to perform 132 HTTP transactions. The main domain is shoetimewholesale.com and was registered 21 years ago.

Submitted URL: https://shoetimewholesale.com

Effective URL:

http://www.shoetimewholesale.com/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Compromised/hijacked storefront weaponized with EtherHiding blockchain malware, fake reCAPTCHA and PowerShell-paste ClickFix; critical IDS malware alerts and malware-tagged domains confirm malicious intent.

Risk Factors (5)
Critical IDS malware signature (EtherHiding Exfil) repeated 10 times
Blockchain RPC connectivity paired with the ClickFix PowerShell/PowerShell-paste social engineering
eval() dynamic code execution on the page
Malware threat-intel labels (vidar, clearfake) associated with loaded/primary domains
Circular redirect signal
Domain age information unavailable

Details

Page Title

Welcome Shoe Time Wholesale

Scan Type

public

Domain Name Analysis

The domain 'shoetimewholesale.com' uses the commercial generic top-level domain (.com) with no subdomain. Its registrable label 'shoetimewholesale' stretches across 17 characters containing 8 vowels alongside 9 consonants. It segments into 3 words: shoe, time, wholesale. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://shoetimewholesale.com

Page Load Overview

13.68s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,973 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
18173.254.30.178Phoenix, Arizona, United States
AS31898Oracle Corporation
6142.251.20.95Google · CDNUnited States
AS15169Google LLC
6192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
6192.0.77.2San Francisco, California, United States
AS2635Automattic, Inc
6142.251.13.95Google · CDNUnited States
AS15169Google LLC
6172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6216.239.38.178Google · CDNUnited States
AS15169Google LLC
6142.251.14.94Google · CDNUnited States
AS15169Google LLC
63.33.155.121Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
615.197.198.189Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
13220--

Detected Technologies14

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17FA362ABF2C454AF653F8959829DB77CFC3CA140D70A3A95B0E9B3348B8D9EB045521C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:/YypowqRLUYXaldlMlWlBaXD2JOnxn+PZMfGVobhODc:/5hMP

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:101354:ITMRYC0AxhgRPNIBIRgOQQEJQgCAClCSUAANNUoUxAoiTZCTMMldKEyRWRgj3JEyG0IIMCgghAJGIohaAowxAxilgMYRHYAq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Scan History

Scan history not available

Unable to load historical scan data