Security Scan Report: weatherstem.com

Redirected to:
https://company.weatherstem.com/
Site favicon
Submitted: May 13, 2026, 10:09:38 PMCompleted: May 13, 2026, 10:11:20 PMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 1 country across 10 domains to perform 66 HTTP transactions. The main domain is company.weatherstem.com and was registered NaN years ago.

Submitted URL: https://weatherstem.com

Effective URL: https://company.weatherstem.com/Redirected

The Cisco Umbrella rank of the primary domain is #326,616 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Site shows strong malware indicators (critical IDS alerts, C2 beacon) despite being an old, self‑branded domain; avoid interaction and report.

Risk Factors
Critical IDS alerts (malware data exfiltration)
Critical IDS alerts (potential C2 beacon)
High JavaScript obfuscation score
Domain ranking #326,616 (well below top 10k for a brand)
Multiple redirects (2) to subdomain
Domain age information unavailable

Details

Page Title

Weatherstem

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(63%)

Domain Information

You're looking at domain 'weatherstem.com' on the commercial generic top-level domain (.com). The second-level label 'weatherstem' is 11 characters long containing four vowels alongside 7 consonants. Tokenizing the label suggests 2 words: weather, stem. Median word length comes out to 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://weatherstem.com

Page Load Overview

7.02s
Total Load Time
127
HTTP Requests
19
Domains
5.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:11,173 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software63% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
63%
government public service
55%
documentation technical
38%
corporate
35%
healthcare medical
32%

Detected Features

Articles
Comments
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15192.0.78.20San Francisco, California, United States
AS2635Automattic, Inc
1465.8.131.51United States
AS16509Amazon.com, Inc.
14192.0.77.32San Francisco, California, United States
AS2635Automattic, Inc
14192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
14216.127.151.209Frederick, Maryland, United States
AS13694Xecunet, LLC.
14216.127.151.218Frederick, Maryland, United States
AS13694Xecunet, LLC.
14192.178.183.91United States
AS15169Google LLC
14192.0.77.2San Francisco, California, United States
AS2635Automattic, Inc
14142.251.110.97United States
AS15169Google LLC
1279--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17974A3717D670436312F13CFA00B639C6056EFDADAA5A7E1F4B16124A7F2DA036F2258

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:0QEd7jJrwy7KgQF9jbqKGZxMpSd75itfDo/u06d7zjLfuKjgN5VcwjbqKGZxMpf5:0QKiE91

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:353978:AhUVAACNIRLiuQlMkBEY0SzIVYDfG0hUlhIGOMBE4yIkJQMBQEolyohgJgC1SchIYIhJAQNQTMAqKIAIA0okxKEXHAEhIiJK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff030313070100f7
Perceptual Hash:ac99d312ec45e5d2
Difference Hash:bd3ba3272d6ffd27
Wavelet Hash:ff072313170700ff
Color Hash:#1f8693

Scan History

Scan history not available

Unable to load historical scan data