Security Scan Report: buletinnews.id

Site favicon
Submitted: Sep 21, 2026, 6:47:26 AMCompleted: Sep 21, 2026, 6:48:23 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 76%

8
Risk Score

Legitimate-looking Indonesian news portal that appears compromised: its domain is flagged as a malware loader and it fires EtherHiding/blockchain C2 traffic plus a ClearFake exploit-kit resource. Avoid.

Risk Factors (5)
Domain registered 0 days ago (CRITICAL age category, 3x multiplier) yet publishes a full archive of local news
Content-malware Indicator of Compromise on the primary domain
CRITICAL IDS malware alerts (EtherHiding) plus blockchain RPC / smart-contract call traffic
Exploit-kit (ClearFake) address referenced among loaded resources
eval()/Function() obfuscation with a network sink
Domain age information unavailable

Details

Page Title

BuletinNews.id - Portal Berita Terkini

Scan Type

public

Domain Name Analysis

The domain name 'buletinnews.id' uses the Indonesian country-code top-level domain (.id) while skipping any subdomain. The core label 'buletinnews' covers 11 characters holding 4 vowels versus seven consonants. Breaking it apart gives 4 words: bu, let, in, news. Median word length comes out to 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://buletinnews.id

Page Load Overview

9.73s
Total Load Time
3.3 MB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:id
Text Length:78,691 chars
Detector Agreement:40%

Website Classification

Primary Category

government public service75% confidence
Type: spa
Method: ml+structural

All Detected Categories

government public service
75%
education learning
61%
corporate
35%
news/blog
20%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10103.16.198.171Indonesia
AS131775PT. Jupiter Jala Arta
6142.251.13.95Google · CDNUnited States
AS15169Google LLC
6142.251.20.97Google · CDNUnited States
AS15169Google LLC
6142.251.110.155Google · CDNUnited States
AS15169Google LLC
6142.251.110.156Google · CDNUnited States
AS15169Google LLC
6104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6172.64.147.103Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6192.178.183.94Google · CDNUnited States
AS15169Google LLC
6216.239.34.36Google · CDNUnited States
AS15169Google LLC
6142.251.20.101Google · CDNUnited States
AS15169Google LLC
12420--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F9050A32B640143FE73B45C4D288AB0E72D6A32FF5E44450F7E607AC86E5EB8652E257

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:Ro+QwHyzR1zSkAo5XBIY5zFBiac52m7lT:R6jzSAXauk/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:850656:ECS+BbAhnJEhJIEIPKXUNEUsIgJEGRMADXSRCJUjBCUCxGDXZQyJMWgBUshpHREAEAC1lgSKEqNwfAsgQqAgQ0gnETkKiSiK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc3c3c3c7ffc3c3
Perceptual Hash:b870c7cf368d9a30
Difference Hash:349e9e9ebe129a9f
Wavelet Hash:d7c3c3c3c3c34343
Color Hash:#1f9370

Scan History

Scan history not available

Unable to load historical scan data