Security Scan Report: nguyencanhkhanh.com

Site favicon
Submitted: Sep 16, 2026, 7:47:28 AMCompleted: Sep 16, 2026, 7:48:17 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Malware-distribution risk: CRITICAL EtherHiding exfil IDS hit, Ethereum RPC endpoint, and malware IoCs on the primary domain and a loaded resource (xaz2.com). Avoid interaction.

Risk Factors (5)
CRITICAL malware IDS signature (EtherHiding exfiltration) tied to the scanned page
Primary domain flagged as malware loader by threat intelligence
Malicious third-party resource (xaz2.com / iclickfix) loaded by the page
Ethereum RPC/blockchain domain used for covert payload/exfil channels
Unranked domain with no established reputation
Domain age information unavailable

Details

Page Title

Trang chủ - nguyễn cảnh khánh

Scan Type

public

Domain Name Analysis

The domain 'nguyencanhkhanh.com' uses the commercial generic top-level domain (.com) and has no subdomain. Count 15 characters in 'nguyencanhkhanh' holding four vowels versus 11 consonants. Tokenizing the label suggests five words: nguyen, can, h, khan, h. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nguyencanhkhanh.com

Page Load Overview

6.78s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇻🇳Vietnamese
Code: vi
Confidence:50%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:597 chars
Detector Agreement:100%
Language mismatch: Declared as en-US but detected as vi

Website Classification

Primary Category

social media network49% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

social media network
49%
finance banking
37%
corporate
35%
education learning
33%
e-commerce shopping
28%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12142.251.20.97Google · CDNUnited States
AS15169Google LLC
220.250.198.32Azure · CLOUDZurich, Zurich, Switzerland
AS8075Microsoft Corporation
2103.82.64.61Sydney, New South Wales, Australia
AS38220Amaze Intelligence
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.171.87.38Azure · CLOUDDulles, Virginia, United States
AS8075Microsoft Corporation
2142.251.127.149Google · CDNUnited States
AS15169Google LLC
2146.19.24.104Poland
AS201814MEVSPACE sp. z o.o.
2142.251.153.4Google · CDNUnited States
AS15169Google LLC
2142.251.155.4Google · CDNUnited States
AS15169Google LLC
2142.251.110.94Google · CDNUnited States
AS15169Google LLC
5020--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F0E21A31D19404E13F2EC76DB6F2B2389698A625C5076BA3B0FE345C5A185FB10E3A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:+eV9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyfECs7dqM2WmFOr4r/ZdSZUaAfkWe:+eV9i5Q62I/xE6x4g5bn/2scW0Zdyp6e

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31597:ghQQ0YRZYYgAIkI5CCEEYCqJhmI3mDKhQmhMEiAswAFNFHVICoQugADog1Ug4PLgAbAMHQ8wGGAoYgIFo0JQAeSGcpECCULU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000040efc0400ff
Perceptual Hash:9237ed69d436924a
Difference Hash:5156cd1cbda90569
Wavelet Hash:00020cfeff0f05ff
Color Hash:#c5aa87

Scan History

Scan history not available

Unable to load historical scan data