Security Scan Report: heatingsolutionsni.com

Site favicon
Submitted: Oct 1, 2026, 1:35:57 PMCompleted: Oct 1, 2026, 1:36:59 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Compromised heating-business site serving an analyst-confirmed ClickFix WinX overlay: fake Cloudflare verification pushes visitors to paste malware in Terminal, with EtherHiding exfil and multi-feed malware Components of Compromise.

Risk Factors (5)
Injected fake Cloudflare 'Human Verification' overlay (ClickFix) telling users to run a copied command in Windows Terminal
EtherHiding malware exfiltration alert (ET MALWARE EtherHiding Exfil M2) and blockchain RPC calls used to fetch a second-stage payload
Known-malicious kit roster match for family clickfix-winx-overlay-2026-10
Multi-feed threat-intel Components of Compromise on the primary domain and URL
Legitimate heating business site appears compromised and is serving attacker-controlled content
Domain age information unavailable

Details

Page Title

Boiler Repair Belfast | Heating & Plumbing Solutions NI Belfast Heating

Scan Type

public

Domain Name Analysis

Domain 'heatingsolutionsni.com' uses the commercial generic top-level domain (.com) without a subdomain. The second-level label 'heatingsolutionsni' is 18 characters long with eight vowels and 10 consonants. Word splitting yields three words: heating, solutions, ni. Median word length comes out to 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://heatingsolutionsni.com/

Page Load Overview

5.48s
Total Load Time
3.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,274 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate50% confidence
Type: spa
Method: structural

All Detected Categories

corporate
50%
news/blog
40%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
772.61.203.68Manchester, England, United Kingdom
AS47583Hostinger International Limited
4104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.21.27.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4192.178.170.95Google · CDNUnited States
AS15169Google LLC
4172.67.71.102Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4142.251.14.97Google · CDNUnited States
AS15169Google LLC
4152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
4142.251.110.94Google · CDNUnited States
AS15169Google LLC
435.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
4178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
8721--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F12409DF9BB6317D71078354F991632492BCC033DA5B58E5BCBE92198FC26A201BB11E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:aekw54kArdczE6o16pJOwpvBkrnd2DB+gK68Sek3s7+UhHOoFSHr:bR4kQSr

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:218204:KNBACgmaCIbJBE0CkOGSYQQQAPfVhBUASCCRDhFDESBOAmRGRZBFcmPFwFCQKi0iWIwAIQvAQRGgsxRQNDEGAwkSECCTRcMI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:8900ffb3f3f9fbff
Perceptual Hash:ed121369b6ad9ae0
Difference Hash:6bc8332727735300
Wavelet Hash:00009f91f1b1f9ff
Color Hash:#acd279

Scan History

Scan history not available

Unable to load historical scan data