Security Scan Report: koun.org

Site favicon
Submitted: Sep 14, 2026, 9:47:25 AMCompleted: Sep 14, 2026, 9:49:00 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate Koun NGO site appears compromised: CRITICAL EtherHiding exfiltration alerts plus loaded exploit-kit domains indicate injected blockchain-based malware. Avoid interaction; do not submit the contact form.

Risk Factors
CRITICAL EtherHiding malware exfiltration alerts (6x) on the loaded page
Exploit-kit ('ek clearfake-1') domains loaded as page sub-resources
Malicious host 178.16.52.101 reached via page sub-resource
Ethereum RPC / smart-contract retrieval activity and Function() code-generation of unclear origin
Domain age information unavailable

Details

Page Title

Koun - Promoting yoga in underprivileged communities in Lebanon

Scan Type

public

Domain Name Analysis

Within the non-profit oriented generic top-level domain (.org), 'koun.org' is registered and has no subdomain. Its registrable label 'koun' stretches across 4 characters split between 2 vowels and two consonants. Word splitting yields 2 words: kou, n. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://koun.org

Page Load Overview

75.17s
Total Load Time
3.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,938 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.154.119Google · CDNUnited States
AS15169Google LLC
335.232.118.32Google · CDNCouncil Bluffs, Iowa, United States
AS396982Google LLC
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
3104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.151.119Google · CDNUnited States
AS15169Google LLC
32.16.10.86Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
3104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8727--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T198C3295F97B6317872138759FEDA6728836CC23395124DEA7922914C8F81AF710BB21F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:m1mrjooZ0WDXy0a3YtZW0qI0cZdypaTkrsjlvImIB2wAtvDh56j/fju48+dicXjd:3r0oZPXdtk0z0syprrwnwS70fju48+Rx

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:122126:VUAEAKAUlSABUlCExAxEogGIiKQojDhiuwAi8C8OFCJghHAoTi0MBElAz7AWxFQgoEASNKUJJ4+ISABEKWrFArQgC4gdDEID

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000000ffffffffff
Perceptual Hash:c04a499db5377723
Difference Hash:f2d1c9cd088e1e1e
Wavelet Hash:00000000ffffffff
Color Hash:#2dd2c2

Scan History

Scan history not available

Unable to load historical scan data