Security Scan Report: bondibilala.com

Site favicon
Submitted: Oct 2, 2026, 4:25:15 AMCompleted: Oct 2, 2026, 4:25:55 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Established blog that shows signs of compromise: CRITICAL EtherHiding malware IDS alerts, ClearFake-flagged script host, and a clearfake malware IoC on the primary domain. Do not browse; site appears to be serving injected malicious scripts.

Risk Factors (5)
CRITICAL IDS malware alert (EtherHiding exfiltration) on the page
Page loads sub-resources from ClearFake-flagged third-party domain browseid.codes
Blockchain RPC calls consistent with EtherHiding malicious payload retrieval
Primary domain flagged as clearfake malware distribution
HIGH IDS alert for Spamhaus DROP-listed traffic
Domain age information unavailable

Details

Page Title

Bonding with Bondi – A first class seat into my head, life experiences and opinions

Scan Type

public

Domain Name Analysis

You're looking at domain 'bondibilala.com' on the commercial generic top-level domain (.com) without a subdomain. Count 11 characters in 'bondibilala' containing 5 vowels alongside 6 consonants. Word splitting yields 3 words: bondi, bilal, a. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bondibilala.com/

Page Load Overview

3.22s
Total Load Time
810 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,660 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical51% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
51%
blog personal website
50%
government public service
47%
documentation technical
46%
social media network
43%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
877.68.97.186United Kingdom
AS8560IONOS SE
535.214.244.104Google · CDNGroningen, Groningen, Netherlands
AS43515Google Ireland Limited
5188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
5142.251.20.94Google · CDNUnited States
AS15169Google LLC
336--

Detected Technologies5

WordPressv7.1.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10C330975A1DC08B66B0BC39B9494BA2859AEEE35D6136BF9F0FF401493C1CF7402A51E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:fqypyAuRJQ/QD4op+yCU0zXbf7K7G6fc0dXRql:fjjuU4eC7G6U0dXC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:54391:wFABBzFKAvCKxCawMwAMdTJEUARzeSjMKAuAAcGCNRgOiiQVVoQAAADIqyAk0YEQpJsGiNAAFNChABlqRADABYENYOSJGe5l

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:007e7e5e7e7e4252
Perceptual Hash:e4773c672c39286c
Difference Hash:2accd490d4d49696
Wavelet Hash:007e7e5a7a7e4252
Color Hash:#d279c2

Other Hashes

Crop Resistant:2accd490d4d49696

Scan History

Scan history not available

Unable to load historical scan data