Security Scan Report: 24telectrical.co.uk

Site favicon
Submitted: Sep 22, 2026, 7:47:31 AMCompleted: Sep 22, 2026, 7:47:58 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate electrical contractor site likely compromised and serving an EtherHiding blockchain-hosted malware loader; CRITICAL IDS alerts plus malware Indicators of Compromise on qaz0.com/1rpc.io. Avoid interaction.

Risk Factors (5)
EtherHiding malicious-script injection (CRITICAL network IDS alerts)
Malware-typed Indicators of Compromise on loaded resource qaz0.com (multi-feed)
Primary domain itself reported as a RAT/malware host
Page pulls scripts from blockchain RPC domains (1rpc.io) used for EtherHiding
Ethereum Sepolia endpoint (ethereum-sepolia-public.nodies.app) contacted for on-chain payload retrieval
Domain age information unavailable

Details

Page Title

24T Electrical Services

Scan Type

public

Domain Name Analysis

The domain '24telectrical.co.uk' uses the United Kingdom country-code top-level domain (.co.uk) without a subdomain. The registrable portion '24telectrical' spans 13 characters containing four vowels alongside seven consonants, along with two digits. Splitting it apart reveals three words: 24, t, electrical. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://24telectrical.co.uk

Page Load Overview

7.95s
Total Load Time
863 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:4,324 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service65% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
65%
documentation technical
63%
real estate property
31%
corporate business
28%
corporate
25%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
977.68.114.188United Kingdom
AS8560IONOS SE
9142.251.20.95Google · CDNUnited States
AS15169Google LLC
9104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9142.251.14.94Google · CDNUnited States
AS15169Google LLC
9104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
546--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10D82E973038F79821F1C9566BBFEA69C8215A43B2537AF67C44D1AAD20E93EE4051C4B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:rdUqQm0PIlGDzHz8CMe9ihppC5JE97YjrD6AL2C6N:rmqQmsSGDjAxpC5i7Yj/6nB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18058:B7Aa4kggiBJYKGgAGQUIhLW7cAAxEYtiCYNkCGCAQCAhSqAEARHgDPRANYDgHEiA1AGK1AIHAAkodcqBIDElsBAxKhCKgkiJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:40003e3f070727ff
Perceptual Hash:8340e833f847adbe
Difference Hash:c1c1e4cb3c5f4d2a
Wavelet Hash:40203e3f070737ff
Color Hash:#bf9540

Scan History

Scan history not available

Unable to load historical scan data