Security Scan Report: hgpdesign.nl

Site favicon
Submitted: Sep 21, 2026, 5:47:26 AMCompleted: Sep 21, 2026, 5:47:46 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Aged Dutch photography/DTP site appears compromised: critical EtherHiding malware IDS alert, blockchain-RPC load pattern, and malware-flagged external resource xaz2.com. No credential forms; risk is infection, not phishing.

Risk Factors
Critical Suricata malware alert (EtherHiding exfiltration) on the page's network activity
EtherHiding blockchain-RPC pattern (Sepolia testnet RPC gateway in DNS queries and TLS SNI)
Third-party resource xaz2.com flagged as malware by two corroborating feeds
Primary domain carries an (unverified, single-source) malware loader indicator
Domain age information unavailable

Details

Page Title

HGPDESiGN – Fotografie – dtp – betaalbaar

Scan Type

public

Domain Name Analysis

Within the Dutch country-code top-level domain (.nl), 'hgpdesign.nl' is registered without a subdomain. Its registrable label 'hgpdesign' stretches across 9 characters with 2 vowels and seven consonants. Tokenizing the label suggests three words: h, gp, design. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://hgpdesign.nl

Page Load Overview

2.08s
Total Load Time
3.6 MB
Total Size

Language Analysis

Primary Language

🇳🇱Dutch
Code: nl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:nl-NL
Text Length:2,088 chars
Detector Agreement:50%

Website Classification

Primary Category

government public service71% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
71%
news media journalism
70%
adult content
69%
entertainment media
67%
technology software
61%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1281.169.145.152Germany
AS6724Strato GmbH
8142.250.154.95Google · CDNUnited States
AS15169Google LLC
835.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
8188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8142.251.14.94Google · CDNUnited States
AS15169Google LLC
445--

Detected Technologies6

WordPressv7.0.2
100%
JQueryv3.7.1
100%
50%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B3F2CA31E1A401A57E1F9B6DF1D6F3386684BA15C9027BB770F9306849989FB00B771E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Nq9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDy7D2WmFNr0ZdSZUaAwGWaHSkW7L1q/U:89i5Q62I/xE6x4g5bn/rWDZdyp/H7f9D

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:36199:pIMgYQQBaMxIaIaASAIQYAaRLRVKQCRIDTgBE4SH8iiqwMQBOhqfbRLhkEDxBNgkKBrJlWgFCUAHQdgIApCagYCKAR0AIMAo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0000000000ffff
Perceptual Hash:9a2de548d1a1caf6
Difference Hash:23173d3834714f4c
Wavelet Hash:ff01010c0c18ffff
Color Hash:#bf9540

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data