Security Scan Report: dxghq.com

Site favicon
Submitted: Sep 20, 2026, 3:47:26 AMCompleted: Sep 20, 2026, 3:48:14 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Legitimate-looking DXG agency site has been compromised: ClearFake/EtherHiding malware — blockchain-based C2, a fake Cloudflare 'verification' page coaching terminal commands (ClickFix), and a CRITICAL EtherHiding IDS alert. Do not interact.

Risk Factors (6)
CRITICAL IDS malware alert (ET MALWARE EtherHiding Exfil) on the scanned page's traffic
ClearFake-labelled third-party domain (wmicconfidance.info) loaded by the page
EtherHiding blockchain C2 pattern: Tenderly polygon RPC gateway + Ethereum getDomain() contract request
Fake verification page coaching the user through keyboard/terminal steps (ClickFix-style drive-by infection)
Primary domain flagged as malware ('iclickfix') in threat intelligence
Dynamic Function() constructor code generation on a marketing site
Domain age information unavailable

Details

Page Title

DXG | Experience Innovation & Digital Transformation Agency

Scan Type

public

Domain Name Analysis

Domain 'dxghq.com' uses the commercial generic top-level domain (.com) without a subdomain. The registrable portion 'dxghq' spans 5 characters holding zero vowels versus 5 consonants. Tokenizing the label suggests 2 words: dx, ghq. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dxghq.com

Page Load Overview

8.74s
Total Load Time
5.9 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:2,806 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software76% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
76%
corporate business
73%
corporate
35%
government public service
30%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15151.101.130.159Fastly · CDNUnited States
AS54113Fastly, Inc.
9142.251.155.119Google · CDNUnited States
AS15169Google LLC
9142.251.150.119Google · CDNUnited States
AS15169Google LLC
9142.251.127.97Google · CDNUnited States
AS15169Google LLC
9216.239.32.36Google · CDNUnited States
AS15169Google LLC
9192.178.183.94Google · CDNUnited States
AS15169Google LLC
935.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
9178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
788--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T190A29473A09645167B6ED7EDC5C3731CD958A607CA05E7BA70F4201886E8AFB00F762E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:PK7jkmep+EElO0iiX25rqwRXdSZsTaAh369K3h1TNslQCfEGHRmy4kW2HMR2Sz3j:ujk4EElO0iiX25r/ZdSZUaAhDkWfN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21411:EG0+CRQCNWYoCN3ZSiAQAhgYACSgYlIoIpQk+APAQlQQI2VJXAAJugwTTGWUCQq0gJrGJJRPAAjaLBJpRG7NYBC6s6VIYAU4

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffc1818181
Perceptual Hash:aac43d3d9191cec6
Difference Hash:96e7e1d103032b2b
Wavelet Hash:7f79fff941010101
Color Hash:#ac6553

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data