Security Scan Report: etta-textservice.de

Site favicon
Submitted: Sep 19, 2026, 5:47:30 PMCompleted: Sep 19, 2026, 5:47:48 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Legitimate-looking German proofreading site whose domain is flagged as a stealer and which loads malware-flagged xaz2.com plus EtherHiding blockchain exfil traffic — likely compromised and serving malware.

Risk Factors (4)
Content-malware threat-intel match on the primary domain (stealer)
Multi-source corroborated malware indicator on loaded third-party domain xaz2.com (iclickfix)
CRITICAL network IDS malware/EtherHiding exfiltration alert
External Ethereum RPC endpoint loaded, a hallmark of EtherHiding C2 techniques
Domain age information unavailable

Details

Page Title

Etta Textservice

Scan Type

public

Domain Name Analysis

Within the German country-code top-level domain (.de), 'etta-textservice.de' is registered while skipping any subdomain. Its registrable label 'etta-textservice' stretches across 16 characters containing six vowels alongside 9 consonants, notching 1 hyphen. Splitting it apart reveals three words: etta, text, service. Median word length is 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://etta-textservice.de

Page Load Overview

1.18s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:588 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning65% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

education learning
65%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
487.106.73.179Germany
AS8560IONOS SE
4104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
123--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13983C7A183B048F4797F873B6E55A2149617E902CA097BD6F0F7D19474CCAA606E3F0B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:0iCVZclkwGypadIZ3bwemlUVuXwRmVqv6:iVZclkywdIZ3bwemlUVugRmVqv6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:81342:KKQDJAoBsCHgkSooQACGVSAQEwO2YmAJtfiKTOGOSkuxsgBJAjRQhCCACFEMNCQ4cgLCPQhgVpBIhlpU4mBCwCIFUAACGKNA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9fcfcfffc3e7c189
Perceptual Hash:b99638c69cce9638
Difference Hash:269c9c4c960e2b9b
Wavelet Hash:9fc6c6e6c3e38181
Color Hash:#937a1f

Scan History

Scan history not available

Unable to load historical scan data