Security Scan Report: paulusgemeinde-raunheim.de

Site favicon
Submitted: Sep 20, 2026, 3:47:31 PMCompleted: Sep 20, 2026, 3:47:57 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Established German church site appears compromised: critical IDS alert for EtherHiding exfiltration plus blockchain RPC and a malware-flagged third-party domain indicate injected malicious/exfiltrating script.

Risk Factors
Critical IDS malware alert (EtherHiding exfiltration)
External blockchain RPC endpoint loaded alongside flagged malware domain xaz2.com
Threat-intel matches on both the primary domain and a third-party resource it loads
Anti-analysis technique (right-click blocking) combined with crypto script APIs
Likely compromised WordPress installation serving malicious/exfiltrating script
Domain age information unavailable

Details

Page Title

Paulusgemeinde Raunheim | – Evangelisch in Raunheim –

Scan Type

public

Domain Name Analysis

You're looking at domain 'paulusgemeinde-raunheim.de' on the German country-code top-level domain (.de) with no subdomain. The second-level label 'paulusgemeinde-raunheim' is 23 characters long with 11 vowels and eleven consonants, plus 1 hyphen. Word splitting yields five words: paulus, gemeinde, rau, n, heim. Median word length is four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paulusgemeinde-raunheim.de

Page Load Overview

6.36s
Total Load Time
1.3 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:3,654 chars
Detector Agreement:100%

Website Classification

Primary Category

forum community discussion68% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

forum community discussion
68%
news/blog
20%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1281.169.145.68Germany
AS6724Strato GmbH
12104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
363--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15543B63993B465F72EFA939DB98FB2345685BA01CB5BA3F3B05DC054508C59708B2B0E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:Y9i5Q62I/xE6x4g5bn/cWYfD5OhTwH+b0ZrZdypaZWsXD:+iCvhfsCtbypdsXD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:59589:QJE2CQjEgUoYBD4swECAay8ABS3ZBoDGzkE/EACIEgAUKAiiAagRCXAUSnBAAcUzQCIVXvQD8MpjZTIwihCcMAh8SKiBAtMK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00800078787878ff
Perceptual Hash:c97ebe418741b658
Difference Hash:d131b1c1f1f1f193
Wavelet Hash:f8c08078787878ff
Color Hash:#bf9540

Scan History

Scan history not available

Unable to load historical scan data