Security Scan Report: gp-wrightconstruction.com

Site favicon
Submitted: Sep 16, 2026, 3:47:30 AMCompleted: Sep 16, 2026, 3:48:24 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Aged construction site that appears compromised: CRITICAL EtherHiding malware IDS alert, embedded Ethereum RPC exfil endpoint, a flagged third-party script host and a malware report on the primary domain. Do not interact; report.

Risk Factors
CRITICAL network IDS alert for malware (EtherHiding exfiltration)
Blockchain RPC endpoint (ethereum-sepolia-public.nodies.app) embedded on a non-crypto business site — hallmark of EtherHiding loader infrastructure
Threat-intel malware report against the primary domain
Malware-flagged third-party script host (xaz2.com, 2 feeds) loaded on the page
Domain age information unavailable

Details

Page Title

Excavation Contractors Hill County, TX | Pond Builder Texas | Wright Construction

Scan Type

public

Domain Name Analysis

The domain name 'gp-wrightconstruction.com' uses the commercial generic top-level domain (.com) and has no subdomain. Its registrable label 'gp-wrightconstruction' stretches across 21 characters with 5 vowels and 15 consonants, notching one hyphen. Breaking it apart gives 3 words: gp, wright, construction. Expect six characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gp-wrightconstruction.com

Page Load Overview

8.30s
Total Load Time
5.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:9,905 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical74% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
74%
government public service
57%
blog personal website
53%
adult content
26%
corporate
25%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12209.87.159.26United States
AS36444Liquid Web, L.L.C
713.33.187.28Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
7172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7216.239.32.36Google · CDNUnited States
AS15169Google LLC
7142.251.20.97Google · CDNUnited States
AS15169Google LLC
7104.18.19.183Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.14.94Google · CDNUnited States
AS15169Google LLC
713.33.187.110Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
689--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17F540572B4504036A2B31B9AD1D97E1CB177C604FA87D7D471ACB29F23D9E9F8662308

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:m6b/jn7r8JJbmF6KL39Fpfayu8EKlFbjHmD9fVPCyBrspCP4xoAUyOD:Lvn34i6KL39Fpfayu8EOFHGD9fVPCyBd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:282539:QBwIDYogA5CM0R1YAoGBQRAIKAHQyQuAAQoxCL0pBAQAjQSdJKIAxVpI0MUKQ5MGEK2ckgQyTNB4EBoURQJgGaJRkEESEwlw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e0ffe1c0f0f0e0
Perceptual Hash:fa00155c3b37c6ec
Difference Hash:9404050911210000
Wavelet Hash:00fff5e1c0f0e0f8
Color Hash:#8bac53

Scan History

Scan history not available

Unable to load historical scan data