Security Scan Report: bflyarn.com

Submitted: Oct 2, 2026, 4:25:06 AMCompleted: Oct 2, 2026, 4:25:43 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Legitimate yarn blog compromised and now injecting ClickFix fake 'Human Verification' overlay plus an ErrTraffic/Exvicy obfuscated loader and EtherHiding blockchain C2 — do not interact, do not paste anything into Terminal.

Risk Factors (5)
Injected ClickFix fake 'Human Verification' overlay kit on a compromised WordPress page
Injected ErrTraffic/Exvicy obfuscated loader (Base64 blob XOR-decoded and run via new Function)
EtherHiding blockchain C2: page scripts contact rpc-mainnet.matic.quiknode.pro and call an Ethereum getDomain() contract
Threat-intel match on the primary domain bflyarn.com (ClearFake malware)
Third-party resource browseid.codes and IP 178.16.52.101 flagged as ClearFake / exploitation-kit infrastructure
Domain age information unavailable

Details

Page Title

BFL Yarn – Blog for Aisling Yarns

Scan Type

public

Domain Name Analysis

The domain 'bflyarn.com' uses the commercial generic top-level domain (.com) without a subdomain. Count 7 characters in 'bflyarn' holding one vowel versus 6 consonants. Splitting it apart reveals 3 words: b, fly, arn. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bflyarn.com/

Page Load Overview

2.17s
Total Load Time
681 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:6,781 chars
Detector Agreement:75%

Website Classification

Primary Category

technology software26% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
26%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5142.11.204.242United States
AS54290Hostwinds LLC.
3142.251.110.95Google · CDNUnited States
AS15169Google LLC
3192.0.73.2San Francisco, California, United States
AS2635Automattic, Inc
3150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
3142.250.154.94Google · CDNUnited States
AS15169Google LLC
3178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
3142.251.20.94Google · CDNUnited States
AS15169Google LLC
237--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T180035D32E09910773B1F83FD61A4729DE9689538D602AB65B4F871285BD4EFB03B720D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:ioSZdypJNAogu42vZDfWptRdjo3pKpPLiKNaLO9zo3M7dfyJ+b0vLBm:iFypjSRdM3pKpPLiKNaLOxo3M7dfyRm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:40049:FuiSgQBsQA70yImLSCSEBPIpLQKgw0AIwjSyQHMQMSKyChBhacgaNEmAJHAQA8HEwIokzkzAiAxAJCJBSoCUbJkzFNEIAAlk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff9fbfdb8181ffff
Perceptual Hash:bd94d26d69c3232c
Difference Hash:c2222832330f3222
Wavelet Hash:7e9e9f838181ff00
Color Hash:#6a2d86

Other Hashes

Crop Resistant:c2222832330f3222

Scan History

Scan history not available

Unable to load historical scan data