Security Scan Report: elifhavuz.com

Submitted: Sep 16, 2026, 10:47:30 AMCompleted: Sep 16, 2026, 10:48:10 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Established Turkish pool company page shows critical malware/exfiltration IDS alert and loads a malware-flagged external domain; likely compromised, avoid interaction.

Risk Factors (4)
CRITICAL network IDS alert for EtherHiding exfiltration malware
Page loads xaz2.com, an external domain flagged as malware by multiple threat feeds
External Ethereum Sepolia public node domain suggests blockchain-based malware C2/exfiltration
Primary domain has a single-source, unverified malware/RAT threat-intel report
Domain age information unavailable

Details

Page Title

Elif Havuz – Havuz sistemleri ve parçaları

Scan Type

public

Domain Name Analysis

Domain 'elifhavuz.com' uses the commercial generic top-level domain (.com) and has no subdomain. Count 9 characters in 'elifhavuz' holding four vowels versus 5 consonants. Tokenizing the label suggests five words: el, if, ha, v, uz. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://elifhavuz.com

Page Load Overview

13.84s
Total Load Time
2.0 MB
Total Size

Language Analysis

Primary Language

🇹🇷Turkish
Code: tr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:tr
Text Length:1,776 chars
Detector Agreement:75%

Website Classification

Primary Category

corporate business100% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
100%
documentation technical
100%
government public service
100%
blog personal website
100%
healthcare medical
99%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9152.53.254.248Nuremberg, Bavaria, Germany
AS197540netcup GmbH
9142.251.13.95Google · CDNUnited States
AS15169Google LLC
9188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9142.251.14.94Google · CDNUnited States
AS15169Google LLC
9104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
455--

Detected Technologies8

WordPressv7.0.2
100%
JQueryv3.7.1
100%
Bootstrapv7.0.2
100%
50%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1233209B1839679D46E6CEA02BBF7B96C0646AC3B043379D7C10F2D8D293A4DB9105D63

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:VRL17llXbDN6BMD+gkdJfVzf4sJ2HQn/xE6oAi5a8zlvg/dP/xB/nkWHHDZUs:VRL1J9fNwMKDfNQ62Ho/xE6x4aUg/5jd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11347:AlC0GMcA2A5CokUkSMWYJUiCMGIGDGIjahOgMDLEDQeABQCQBIByBJALmNkEKbhgZiRk4o4oAwShaTGKhaCZBkSDaJCAMesQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Scan History

Scan history not available

Unable to load historical scan data