Security Scan Report: wordpresshjalp.se

Submitted: Oct 1, 2026, 4:57:29 PMCompleted: Oct 1, 2026, 4:58:07 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

9
Risk Score

Established Swedish WordPress-help site appears compromised, injecting ClearFake/EtherHiding malware via blockchain RPC, with a CRITICAL malware IDS alert and a multi-feed confirmed-malware resource.

Risk Factors (5)
CRITICAL IDS malware alert for EtherHiding exfiltration
ClearFake malware domain loaded as a resource, corroborated by two threat feeds
Blockchain RPC (polygon.drpc.org) usage consistent with EtherHiding payload retrieval
Hacked WordPress instance serving injected spam/SEO content
Obfuscated JS usage heuristics fired (informational, corroborated by malware IDS)
Domain age information unavailable

Details

Page Title

Wordpresshjälp - När du får problem med Wordpress

Scan Type

public

Domain Name Analysis

You're looking at domain 'wordpresshjalp.se' on the Swedish country-code top-level domain (.se) without a subdomain. Its registrable label 'wordpresshjalp' stretches across 14 characters containing 3 vowels alongside 11 consonants. Segmentation suggests 3 words: wordpress, hj, alp. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://wordpresshjalp.se/

Page Load Overview

3.40s
Total Load Time
489 KB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:sv-SE
Text Length:4,713 chars
Detector Agreement:50%

Website Classification

Primary Category

gambling betting97% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
97%
entertainment media
96%
education learning
84%
government public service
82%
blog personal website
82%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1265.21.122.251Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
8142.251.20.95Google · CDNUnited States
AS15169Google LLC
8142.251.13.94Google · CDNUnited States
AS15169Google LLC
8192.0.77.48San Francisco, California, United States
AS2635Automattic, Inc
8104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8149.56.95.166Montreal, Quebec, Canada
AS16276OVH SAS
526--

Detected Technologies6

WordPressv7.1.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T137041970BB541D75222B03BEE4A7FA0855798523DA0D5AF9F8FFD04885C2FE261B160E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:GZNVAw9pc+SN+W2Z55//2lRW3Tfo3VLGz0Jo:Lw9O+SN4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:177775:oBAg1gxUAaMRBSSgIhaiEACFcsgCCARCM6AgCTBEgoFPDliFTECQEgCICgacCHAOJSVA/cBI2EGBEawZqCAGgwhISEUuQCMA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff8283fb8387df87
Perceptual Hash:bdc1c6c0cfc03ae3
Difference Hash:423a3a123a3e3c2c
Wavelet Hash:ff8081b98183bf87
Color Hash:#d2692d

Other Hashes

Crop Resistant:423a3a123a3e3c2c

Scan History

Scan history not available

Unable to load historical scan data