Security Scan Report: religija.lt

Site favicon
Submitted: Sep 21, 2026, 4:47:27 AMCompleted: Sep 21, 2026, 4:48:10 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate 23-year-old Lithuanian religious-studies site appears compromised: a CRITICAL IDS alert for EtherHiding malware exfiltration and a malware-flagged blockchain RPC/malicious script are loaded on the page. Avoid interaction until cleaned.

Risk Factors (4)
Network IDS CRITICAL: ET MALWARE EtherHiding Exfil M2 (trojan exfiltration)
Injected/loaded script contacting blockchain RPC gateway (gateway.tenderly.co) — EtherHiding payload delivery
External resource xaz2.com flagged as malware (iclickfix) by two independent threat feeds
Primary domain flagged for RAT/malware by threat-intel feed
Domain age information unavailable

Details

Page Title

Titulinis | Religijų tyrimų ir informacijos centras

Scan Type

public

Domain Name Analysis

The domain 'religija.lt' uses the Lithuanian country-code top-level domain (.lt). The second-level label 'religija' is 8 characters long split between four vowels and four consonants. Word splitting yields 3 words: re, lig, ija. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://religija.lt

Page Load Overview

6.33s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇱🇹LT
Code: lt
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:lt-LT
Text Length:5,862 chars
Detector Agreement:75%

Website Classification

Primary Category

download file sharing43% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

download file sharing
43%
corporate
35%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8185.5.53.49Vilnius, Vilnius, Lithuania
AS212531UAB Interneto vizija
5142.251.13.95Google · CDNUnited States
AS15169Google LLC
5142.251.13.97Google · CDNUnited States
AS15169Google LLC
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.14.94Google · CDNUnited States
AS15169Google LLC
5216.239.34.36Google · CDNUnited States
AS15169Google LLC
387--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C0D2F772D19400923F1DC7ADF2E6B33C9568B619C91277A7B0BD306C59686F700A7A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:CR9i5Q62I/xE6x4g5bn/MAA+9dSWDZdypa95:CfiCrc9oYypU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29864:IT0VkEQgMMIBNhERACVgZ60K2ANtN7kACAEoApDWBRAgUhxAAByxQCiSZ0qpAABI4MEJclErKmMyKmiEUEA0AUgjI0DC+f5T

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Scan History

Scan history not available

Unable to load historical scan data