Security Scan Report: shop.use-domer-fotografie.de

Site favicon
Submitted: Sep 21, 2026, 1:47:32 AMCompleted: Sep 21, 2026, 1:48:01 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate German photography shop that appears compromised: CRITICAL EtherHiding exfiltration alert, a Sepolia blockchain RPC connection, and a malware-flagged external resource (xaz2.com). Treat as malicious.

Risk Factors (4)
Critical IDS malware/EtherHiding exfiltration alert
Blockchain RPC connection consistent with EtherHiding malware technique
External resource xaz2.com (multi-source malware) loaded by the page
Threat-intel malware report against the primary domain (single-source)
Domain age information unavailable

Details

Page Title

Usedom Bilder und Kalender online bestellen - Use Domer Fotografie Shop

Scan Type

public

Domain Name Analysis

You're looking at domain 'shop.use-domer-fotografie.de' on the German country-code top-level domain (.de) with subdomain 'shop'. Its registrable label 'use-domer-fotografie' stretches across 20 characters with nine vowels and 9 consonants; bonus characters include 2 hyphens. Word splitting yields six words: use, do, mer, fotogr, a, fie. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://shop.use-domer-fotografie.de

Page Load Overview

9.59s
Total Load Time
5.4 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:4,885 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate50% confidence
Type: spa
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
20217.160.0.14Germany
AS8560IONOS SE
20172.67.68.196Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
20188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
603--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T143E2F832F05410A23FCE9B7CE1A2F63C9559D6059506BBB7B1F8309D48986FB10A7A1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:w9i5Q62I/xE6x4g5bn/2UHC9LSoQaf5qlcdgHZqGcSBvB4BlBjKkJ3jIHZdypaya:miCh2ypFM

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33461:GIIlzkAIJqUiAEIoAA0ACWBw8YwNAGRq0hzhrMJclQMYAgADIi4+KsKCEhEkEAuGAAESKQxGuhiEU5wjUMFBT4iXwAASAFHA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:005ef0f08080ffff
Perceptual Hash:d840833c7fc3627e
Difference Hash:88b080503030008c
Wavelet Hash:005ff0f08080ffff
Color Hash:#2dd28d

Scan History

Scan history not available

Unable to load historical scan data