Security Scan Report: knoxvol.com

Site favicon
Submitted: Sep 21, 2026, 9:47:29 AMCompleted: Sep 21, 2026, 9:47:51 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Malware-distribution page: critical EtherHiding blockchain exfil alert plus stealer/malware Indicators of Compromise on its own and loaded domains, while impersonating Google Workspace. Avoid.

Risk Factors (5)
Critical IDS malware/trojan alert (EtherHiding exfiltration)
Blockchain RPC connection consistent with EtherHiding malware
Content-malware Indicators of Compromise on primary domain (stealer)
Malware-flagged external resource loaded by the page
Unauthorized Google Workspace brand/partner impersonation
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Domain 'knoxvol.com' uses the commercial generic top-level domain (.com). Count 7 characters in 'knoxvol' split between two vowels and 5 consonants. It segments into two words: knox, vol. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://knoxvol.com

Page Load Overview

3.81s
Total Load Time
253 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,461 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
50%
documentation technical
43%
corporate business
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3100.26.25.97Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
3104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3192.0.77.48San Francisco, California, United States
AS2635Automattic, Inc
124--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C083C8A197B018F5397F83376F51A2146627D903C50976E5F0F7E2946B8CEA206E3B0B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:HiCjBcmRiBmgT0cTrnbO27ki5ypeyZobXemlUVuXwamGZobFemlUVuXwam74wCAx:PjBcmRiBmgT0cTrnbO27ki0/ZobXemlh

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:86811:wgDAB2OGSUNmcAGhICBYACsMRlYCE4EaARjgAAwSCkijI0Nk7IKqJELGAgiwCwvgHAhFCx+IEMaBkAVEDCiKzMQCYgBAlBhc

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe3e38f8383dfff
Perceptual Hash:b963c31ccc923373
Difference Hash:060f4b2c2a32200c
Wavelet Hash:e3e1e18381819fe7
Color Hash:#1f6793

Other Hashes

Crop Resistant:060f4b2c2a32200c

Scan History

Scan history not available

Unable to load historical scan data