Security Scan Report: betiwin168.com

Site favicon
Submitted: Sep 17, 2026, 1:47:32 PMCompleted: Sep 17, 2026, 1:48:18 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

EtherHiding/C2 malware indicators: CRITICAL IDS exfil alert, blockchain RPC connection, and multi-source malware threat-intel on loaded resource qaz0.com and primary domain betiwin168.com.

Risk Factors (5)
Critical network IDS malware alert (EtherHiding Exfil M2)
Blockchain RPC connection to rpc.sepolia.ethpandaops.io indicating EtherHiding-style hidden payload
Multi-source malware threat-intel match on loaded resource qaz0.com
Threat-intel malware match on primary domain betiwin168.com
No Cisco Umbrella ranking despite 6-year-old domain, reused for low-quality vape SEO content
Domain age information unavailable

Details

Page Title

LANA-LANA電子煙-LANA煙彈-lana-糖果|小七糖果電子煙 - 只是一個 LANA-LANA電子煙-LANA煙彈-lana-糖果|小七糖果電子煙WordPress 網站

Scan Type

public

Domain Name Analysis

The domain name 'betiwin168.com' uses the commercial generic top-level domain (.com) with no subdomain. Its registrable label 'betiwin168' stretches across 10 characters holding 3 vowels versus 4 consonants, plus 3 digits. Segmentation suggests four words: be, tiw, in, 168. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://betiwin168.com

Page Load Overview

8.92s
Total Load Time
885 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-TW
Text Length:6,088 chars
Detector Agreement:60%

Website Classification

Primary Category

adult content48% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

adult content
48%
entertainment media
47%
technology software
42%
blog personal website
34%
healthcare medical
33%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9103.17.8.35Taiwan
AS131149Yuan-Jhen Info., Co., Ltd
7192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
7104.26.12.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
304--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T134D20932D1C924927F1DC77DF3A1B32C5258A5159903BB27B0E532ACA5586FF00A7A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:odUqQm0PIlGDzHz8CMe9ihp7EQLCjo2/Twr/ZdSZUaAskWe7:omqQmsSGDjAxV8ofZdypJA

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28440:xtDhgEBgAOK0kmaAAcSIAngMRWAYCWhwQACRMggEDCQgiJU1ITIACifVDCMAQIAoZC0Jk2WLpqmUQwGBwQHMYeHdgRMAGQTg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff81818383ff9fff
Perceptual Hash:be6cc191939ec13c
Difference Hash:1027272f2f2b383c
Wavelet Hash:ff818181819f8f8f
Color Hash:#862d43

Scan History

Scan history not available

Unable to load historical scan data