Security Scan Report: malware.wicar.org

Redirected to: https://www.troyhunt.com/i-now-own-the-coinhive-domain-heres-how-im-fighting-cryptojacking-and-doing-good-things-with-content-security-policies/

Submitted: Sep 28, 2025, 7:28:08 PMCompleted: Sep 28, 2025, 7:28:28 PMpubliccompleted
Loading additional data...

Summary

This website contacted 129 IPs in 4 countries across 21 domains to perform 50 HTTP transactions. The main domain is troyhunt.com and was registered NaN years ago.

Submitted URL: http://malware.wicar.org/data/js_crypto_miner.html

Effective URL: https://www.troyhunt.com/i-now-own-the-coinhive-domain-heres-how-im-fighting-cryptojacking-and-doing-good-things-with-content-security-policies/Redirected

AI Security Verdict

Safe Website

Confidence: 92%

1
Risk Score

The page hosts legitimate security content; the redirect domain is unranked but shows no malicious behavior.

Safety Factors
Well‑established domain age
Reputable final destination (troyhunt.com)
No malicious Indicators of Compromise
No collection of sensitive data
Domain age information unavailable

Details

Page Title

Troy Hunt: I Now Own the Coinhive Domain. Here's How I'm Fighting Cryptojacking and Doing Good Things with Content Security Policies.

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(54%)

Screenshot

Security scan screenshot of http://malware.wicar.org/data/js_crypto_miner.html

Page Load Overview

1.22s
Total Load Time
50
HTTP Requests
21
Domains
2.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:22,784 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain54% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
54%
news/blog
50%
corporate
35%
technology software
27%

Detected Features

Articles
OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
50151.101.128.134San Francisco, California, United States
AS54113FASTLY
0151.101.0.134San Francisco, California, United States
AS54113FASTLY
0104.16.175.226United States
AS13335CLOUDFLARENET
0104.18.25.41United States
AS13335CLOUDFLARENET
0216.58.206.72United States
AS15169GOOGLE
0216.239.32.36United States
AS15169GOOGLE
0104.18.28.80United States
AS13335CLOUDFLARENET
0146.75.122.49Frankfurt am Main, Hesse, Germany
AS54113FASTLY
0172.217.16.206United States
AS15169GOOGLE
0172.217.18.10United States
AS15169GOOGLE
233129--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1877328B3718812775BC28091727AB38DFB06801BE7518A91F5AC00DD6FC6EAB55773AC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:0Bvg4QhYmVN7sYiiwjbhzQ1b6atc4RX3d/WbncsHAK+XxyCgb:0WtVlXsitYnjP+Xo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:78616:EhCiQQOJwCgKYIAGIRPB5CQAW5Q0cUMAADWpEADcRYETYloEFIZBaRtgIAKJIjSIBEHBhRSJRwYqQYGGEwFRCEAAFHJigklL

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00000000ffffffff
Perceptual Hash:ba2ad5a55528f5a8
Difference Hash:cf7905c96514992c
Wavelet Hash:00000000ffffffff
Color Hash:#b72dd2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data