Security Scan Report: agilecircle.de

Submitted: Sep 20, 2026, 4:47:30 AMCompleted: Sep 20, 2026, 4:47:57 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 84%

8
Risk Score

Established German consulting site appears compromised: CRITICAL EtherHiding malware IDS alert, blockchain RPC C2 connection, and a stealer threat-intel hit on the primary domain plus malicious third-party domain qaz0.com.

Risk Factors
EtherHiding malware exfiltration signature matched by network IDS
Blockchain RPC (Sepolia testnet) connection consistent with EtherHiding C2
Primary domain flagged as stealer/malware in threat intel
External malicious domain qaz0.com loaded by the page (2 corroborating feeds)
Obfuscated inline scripts, right-click blocking and anti-analysis behaviour on an otherwise simple brochure site
Domain age information unavailable

Details

Page Title

Wege in neue Arbeitswelten – Organisation neu denken

Scan Type

public

Domain Name Analysis

Domain 'agilecircle.de' uses the German country-code top-level domain (.de) with no subdomain. The second-level label 'agilecircle' is 11 characters long holding 5 vowels versus six consonants. Tokenizing the label suggests 2 words: agile, circle. Median word length comes out to 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://agilecircle.de

Page Load Overview

7.73s
Total Load Time
520 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:3,219 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business89% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

corporate business
89%
documentation technical
88%
technology software
51%
government public service
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
881.169.145.152Germany
AS6724Strato GmbH
6172.67.68.196Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T107A30B1113F548FD79EF9B695A2CE718730AAD01C5495BEBF0BAD054628CDE608B3F0A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Z5kxeNmeJGpi36DdXELiGLaZmJyp5Zn/g8UGPE0Z3bcemlUVuXwRmt4aNURdVejJ:Z5kY4eJc79Z3bcemlUVugRmtud0J

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:105134:AME4ISCiArQhAMIQ5AIAEQQ4ZBqvoHMoJwBZHKAhYGosBVcJCoKNEUiEVRI4UhoEARCKcNwTIAGGeFBARBAIRQCEAdhNIQJo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff000000ffffffff
Perceptual Hash:8104c8fcfd1e3eb8
Difference Hash:72c0ddc89614999b
Wavelet Hash:bf000000dffffdc1
Color Hash:#d2797e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data