Security Scan Report: sportorium.ptumb.com

Submitted: Oct 1, 2026, 1:04:58 PMCompleted: Oct 1, 2026, 1:06:08 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Legitimate Indonesian rental site compromised: injected ErrTraffic/Exvicy WordPress ClickFix loader, fake Cloudflare verification telling users to run Terminal commands, plus CRITICAL EtherHiding IDS alert and multi-source malicious Indicators of Compromise.

Risk Factors (5)
Compromised WordPress page serving a known ClickFix/EvilLoader-style injected malicious script
Deceptive Cloudflare-branded verification page used to trick users into running a terminal command
Network IDS CRITICAL malware/EtherHiding exfiltration alert
Page loads multiple threat-intel-flagged malicious domains and IPs
Blockchain RPC (Polygon) connections from the page, a known EtherHiding payload-delivery technique
Domain age information unavailable

Details

Page Title

Unit Usaha Archive - sportorium - PT UMB

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'sportorium.ptumb.com' is registered, featuring subdomain 'sportorium'. Count 5 characters in 'ptumb' holding 1 vowel versus 4 consonants. It segments into two words: pt, umb. Median word length is 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sportorium.ptumb.com/usaha/

Page Load Overview

11.36s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,475 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software27% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
27%
corporate
25%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15147.93.80.15Jakarta, Jakarta, Indonesia
AS47583Hostinger International Limited
13172.217.208.95Google · CDNUnited States
AS15169Google LLC
13132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
13142.251.14.94Google · CDNUnited States
AS15169Google LLC
13178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
13150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
13142.251.13.94Google · CDNUnited States
AS15169Google LLC
937--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15B83C6713C5A1437310F428F92A7371C91D69AE6EE02AAE8F1BE915C57B1EE033E3615

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:APapEEU1316Wqr5R0RuE2EmeZvzfQL7Lap2yiXX3/NwY//1GpgYJzLEJ64PnE02X:AC416WE5Rk2c2OiXXPNwkBkzLEJ64PE1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:88244:NyAUgmhAI4HiGghBIKtFZpVEDEDRBkGCqGCkgKoAsptQEYrJOGpLhpCwBsMHSUhiFyInC0wMPmJAKADRiEwGBxUUg3BGCY0o

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefefee6e6ffffff
Perceptual Hash:d555aa8a77aa8855
Difference Hash:0000000808010101
Wavelet Hash:0e0e1e0e0e1f0f0f
Color Hash:#862d7a

Other Hashes

Crop Resistant:0000000808010101

Scan History

Scan history not available

Unable to load historical scan data