Security Scan Report: beatrizmontes.com

Site favicon
Submitted: Sep 23, 2026, 1:18:18 PMCompleted: Sep 23, 2026, 1:20:14 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate-looking beauty site that has been compromised: page injects gambling/steroid SEO spam and triggers a CRITICAL IDS AMOS infostealer loader hit plus contacts a suspicious .life domain. Avoid interaction.

Risk Factors
CRITICAL IDS malware signature (ET MALWARE AMOS ClickFix Loader) — macOS infostealer loader requested
External suspicious .life domain (ashen-trace-zephyr-draeix.life) contacted by the page
Injected gambling/casino SEO spam links (betr, cosmo casino, neds, mostbet, Lucky8, Mooney Maker, Rabona, Crownplay)
Injected illegal steroid/pharmaceutical spam text
Compromised legitimate site repurposed for spam/malware distribution
Domain age information unavailable

Details

Page Title

Beatriz Montes – Procedimientos y Capacitaciones 🇧🇷🇪🇪🇺🇸🇻🇳Técnicas internacionales | Ultra naturales

Scan Type

public

Domain Name Analysis

The domain 'beatrizmontes.com' uses the commercial generic top-level domain (.com) and has no subdomain. The registrable portion 'beatrizmontes' spans 13 characters split between 5 vowels and eight consonants. Breaking it apart gives 4 words: beat, rizm, on, tes. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://beatrizmontes.com

Page Load Overview

75.17s
Total Load Time
4.9 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es-CO
Text Length:4,241 chars
Detector Agreement:75%

Website Classification

Primary Category

education learning100% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
100%
documentation technical
100%
social media network
100%
adult content
98%
blog personal website
98%

Detected Features

Articles
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15162.241.60.255Vinhedo, São Paulo, Brazil
AS31898Oracle Corporation
132.16.106.7Akamai · CDNAmsterdam, North Holland, Netherlands
AS20940Akamai International B.V.
13142.251.13.95Google · CDNUnited States
AS15169Google LLC
13138.124.60.214Switzerland
AS203273NetCrafters OU
13142.251.14.95Google · CDNUnited States
AS15169Google LLC
13142.251.20.95Google · CDNUnited States
AS15169Google LLC
13184.24.77.135Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
132.16.106.17Akamai · CDNAmsterdam, North Holland, Netherlands
AS20940Akamai International B.V.
1068--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T106B3A8667C17401475AF669FC013A29CA2748CE9D53AB3E6FC719013F0B6DA633E2A17

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:84jhphzEe4ZdypDpPgKVXw2K+a1NlLyuAltqpoI/IwgH7/lAdIjlQoALFdcWQqk5:8vypDWy2KLvEYT1U7/jMX1v

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:117899:RDExCAiAAgAQcSAlBByBFEUMZoCYQKAkF+2CmDEhKkZAJ4ggTkEJtM9ZyDpJADgMQHkiJNHA4AhjcJDEQIOgAMpACCg8CCGK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:41017d7d010101fd
Perceptual Hash:8a64b164dbccd336
Difference Hash:9195e1e115890559
Wavelet Hash:4101797d0101ffff
Color Hash:#86562d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data