Security Scan Report: ufrveterans.com

Submitted: Sep 19, 2026, 7:47:26 AMCompleted: Sep 19, 2026, 7:47:48 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Charity-themed veteran fitness page, but its primary domain is flagged as a malware loader and the page triggers a CRITICAL EtherHiding malware IDS alert while contacting an Ethereum RPC endpoint — likely infected/hosting malicious code.

Risk Factors
Critical IDS malware alert for EtherHiding exfiltration on a page with no legitimate reason to contact a blockchain RPC node
Content-malware threat-intel match on the PRIMARY domain (unknown loader)
Multi-source malware-flagged third-party resource (xaz2.com) loaded by the page
External Ethereum RPC endpoint (nodies.app) indicating potential blockchain-based payload retrieval/exfiltration
Domain age information unavailable

Details

Page Title

United Fitness Recovery – Helping veterans find real recovery through whole-person fitness.

Scan Type

public

Domain Name Analysis

The domain name 'ufrveterans.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. The registrable portion 'ufrveterans' spans 11 characters split between four vowels and seven consonants. Tokenizing the label suggests 3 words: u, fr, veterans. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ufrveterans.com

Page Load Overview

2.91s
Total Load Time
3.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:2,088 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical33% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
33%

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1245.32.199.217Dallas, Texas, United States
AS20473The Constant Company, LLC
8142.250.154.95Google · CDNUnited States
AS15169Google LLC
8142.251.110.95Google · CDNUnited States
AS15169Google LLC
8172.67.70.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8142.251.110.94Google · CDNUnited States
AS15169Google LLC
526--

Detected Technologies6

WordPressv7.0.5
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B823E871E2A000673D2F4FFDF396F118A6687502DA0B27A7B0BDA06945C86F71563B1E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:A9i5Q62I/xE6x4g5bn/bW0QZdypzOkrMDCKLxIpKXvhzFwfVSmCBESEY:WiCyPYypiuCBESEY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:48266:zAIqkigAXAIFxBhdDhjFAAIMZjASJaFMhxzMAABkWAIQEZonAKaEyudWEAtBAMXBBGZqBBshQIANwCBYFJgMjoAlGxwwyiEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff003c0d0c050025
Perceptual Hash:82dce4b4f8ccb8c6
Difference Hash:334df1f9e9ddc5cd
Wavelet Hash:ff003c1f180f256f
Color Hash:#d2797e

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data