Security Scan Report: legalidea.cn

Site favicon
Submitted: Sep 14, 2026, 6:47:32 PMCompleted: Sep 14, 2026, 6:48:11 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Legitimate 6-year-old Chinese law-firm site appears compromised: it loads a malware-flagged third-party domain and an Ethereum RPC endpoint, matching a CRITICAL EtherHiding malware/C2 exfiltration alert. Do not visit.

Risk Factors (6)
Primary domain flagged as malware (RAT) by threat intelligence
External malware-flagged resource (qaz0.com) embedded in page
Critical IDS hit for EtherHiding exfiltration trojan
Blockchain RPC endpoint used, consistent with EtherHiding blockchain-hosted C2
Obfuscated inline JavaScript (encoding/decoding functions)
Domain is unranked in Cisco Umbrella
Domain age information unavailable

Details

Page Title

法律顾问 - 专业法律服务,值得信赖

Scan Type

public

Domain Name Analysis

The domain 'legalidea.cn' uses the Chinese country-code top-level domain (.cn) with no subdomain. Count 9 characters in 'legalidea' with five vowels and 4 consonants. Word splitting yields 2 words: legal, idea. Expect 4.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://legalidea.cn

Page Load Overview

16.35s
Total Load Time
655 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

HTML Lang Attribute:zh-Hans
Text Length:2,176 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business91% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
91%
government public service
52%
corporate
25%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15142.251.14.95Google · CDNUnited States
AS15169Google LLC
9120.55.62.123Hangzhou, Zhejiang, China
AS37963Hangzhou Alibaba Advertising Co.,Ltd.
9104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9163.53.93.47China
AS4812China Telecom (Group)
9192.178.183.94Google · CDNUnited States
AS15169Google LLC
9163.53.93.238China
AS4812China Telecom (Group)
9188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
697--

Detected Technologies7

100%
JQueryv3.7.1
100%
50%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19D333B32E19111A66F6F53BCF1EAA31CA344A503D316AF77B0D82258919CBF350F4A5E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:45kxU4bN/2Fw4ypDWNaECyzMNG5oM4GHNj52I5J51vKRFR:45kn2FwZNM6GU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:51279:IgAUEINL4wq4OOIBfZAQIIIEiTQEVWkQCIIMEqEI5QsCQ1qmykDABjAuErkokJJ4xUFkEBA9AUwAoCRGBYYReHFgA+wgAUQE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fffff7f3c1000000
Perceptual Hash:eee61313e9c414b9
Difference Hash:0b6f272703b55555
Wavelet Hash:fffff7f3c1000000
Color Hash:#421f93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data