Security Scan Report: medicaladvocates.ie

Site favicon
Submitted: Sep 15, 2026, 11:47:32 PMCompleted: Sep 15, 2026, 11:48:05 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate-looking Irish medical legal site, but it loads a multi-feed malware domain (xaz2.com) and a blockchain RPC endpoint, triggering a CRITICAL ET MALWARE EtherHiding alert plus injected gambling spam — signs of compromise serving malware.

Risk Factors (5)
ET MALWARE IDS alert on a page with no legitimate need for blockchain RPC
External malware/ClickFix domain (xaz2.com) referenced by the page
Blockchain RPC (tenderly gateway) used as C2/exfiltration channel (EtherHiding technique)
Injected off-topic gambling spam links in footer — typical hacked-site SEO injection
Crypto-related inline script API present on a legal-services page
Domain age information unavailable

Details

Page Title

MA Guarantee | Medical Advocates Legal Representation | Dublin | Ireland

Scan Type

public

Domain Name Analysis

The domain 'medicaladvocates.ie' uses the Irish country-code top-level domain (.ie) while skipping any subdomain. The core label 'medicaladvocates' covers 16 characters split between seven vowels and nine consonants. Segmentation suggests two words: medical, advocates. Median word length is 8 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://medicaladvocates.ie

Page Load Overview

11.00s
Total Load Time
878 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-GB
Text Length:2,931 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical65% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
65%
government public service
30%
corporate
25%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17194.147.94.25Luxembourg, Luxembourg, Luxembourg
AS213183WHG Hosting Services Ltd
15188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
473--

Detected Technologies7

JQueryv3.7.1
100%
Bootstrapv20160727
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T135E219B2918404967F1EC76CF2E2B36C9554EA15C8077B67B0EE305C4BA85FB01E7A1E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:HRa9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyZIE58z47b4mFa4r/ZdSZUaAfkWLN:U9i5Q62I/xE6x4g5bn/+Z8q48Zdyp6J

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:31584:ZXngDMRzAIDWcCDADhEgogHIJBBrAUgDBiiKBBMCAcAkgUhC4hC1ATCCixTwYQUAAocNgJIJxMviUni4hsDEDeFgiB0iQEQD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00000000c3c3ffff
Perceptual Hash:e91297e912136dd6
Difference Hash:c93133cd03032336
Wavelet Hash:00000000ffffffff
Color Hash:#bf4a40

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data