Security Scan Report: wiltsi.de

Submitted: Sep 13, 2026, 1:47:35 PMCompleted: Sep 13, 2026, 1:47:59 PMpubliccompleted

Summary

This website contacted 3 IPs in 2 countries across 4 domains to perform 1 HTTP transaction. The main domain is wiltsi.de and was registered 10 years ago.

Submitted URL: https://wiltsi.de

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Compromised WordPress site serving ClearFake/EtherHiding malware via blockchain RPC, confirmed by multi-source threat intel on the primary domain and critical IDS malware exfiltration alerts.

Risk Factors
Compromised legitimate WordPress site (default German Gutenberg starter content) used to host ClearFake/EtherHiding malware
Multi-source corroborated content-malware threat intelligence on the primary domain
Critical network IDS malware alerts combined with blockchain RPC smart-contract fetches
Obfuscated inline scripts using Function() constructor and encoding/decoding functions
Domain age information unavailable

Details

Page Title

Startseite – Eine weitere WordPress-Website

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

documentation technical

(67%)

Domain Information

The domain name 'wiltsi.de' uses the German country-code top-level domain (.de) with no subdomain. The core label 'wiltsi' covers 6 characters containing 2 vowels alongside four consonants. Breaking it apart gives 2 words: wilts, i. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://wiltsi.de

Page Load Overview

3.98s
Total Load Time
11
HTTP Requests
4
Domains
524 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:720 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical67% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
67%
adult content
59%
gambling betting
56%
healthcare medical
56%
corporate business
55%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5185.30.32.217Germany
AS48324webgo GmbH
3172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
113--

Page Statistics

11
Requests
3
Unique Domains
549.1 KB
Total Size

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DEF2A531B2F184F97E1F4B7D81A463286954D6018A02ABF6B0F5F1A4A5C89FB04F7B1D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:ZHMeRmw/zzpukwfYBNLbzZdqZUaAVYMIuinaQScS0IkeGJ:d5/zt5YYBNbZdapwYMIuePkk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:34906:fgArkUADNFhEqJA0BmQJUQkAmCQA6MmhPEALOiaeJKQAqcZAEEYwsGgjSETmAkBEMwJbBQmgjL0IwmKBBGihKAAhIQjQUqIX

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00000000ffffffff
Perceptual Hash:ba0aadf44d32929e
Difference Hash:c9cd294904081c20
Wavelet Hash:00000000ffffffff
Color Hash:#87c58d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data