Security Scan Report: paystubsetc.com

Submitted: Sep 21, 2026, 1:47:28 AMCompleted: Sep 21, 2026, 1:47:57 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 87%

8
Risk Score

Established but compromised WordPress site: CRITICAL IDS EtherHiding malware alert, blockchain-RPC exfil and multi-source malware domain xaz2.com, plus the page's own fake pay-stub/landlord-verification services.

Risk Factors
CRITICAL Suricata malware alert (EtherHiding Exfil) on the scanned page
Blockchain RPC exfiltration infrastructure (tenderly.co gateway) queried via DNS and TLS SNI
Multi-source malware-tagged external resource xaz2.com (iclickfix)
Primary domain itself carries a stealer-malware threat-intel report
Content promotes fabricated financial/rental documentation
Domain age information unavailable

Details

Page Title

Pay Stubs Etc - Employment / Rental Verification Service

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'paystubsetc.com' is registered and has no subdomain. Count 11 characters in 'paystubsetc' split between three vowels and 8 consonants. Tokenizing the label suggests 3 words: pay, stubs, etc. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paystubsetc.com

Page Load Overview

9.47s
Total Load Time
575 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:1,911 chars
Detector Agreement:80%

Website Classification

Primary Category

real estate property46% confidence
Type: spa
Method: ml+structural

All Detected Categories

real estate property
46%
government public service
38%
corporate
35%
documentation technical
32%
adult content
32%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14162.210.97.242United States
AS14555LiquidNet US LLC
8142.251.110.101Google · CDNUnited States
AS15169Google LLC
8192.178.183.138Google · CDNUnited States
AS15169Google LLC
835.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
8172.217.114.4Google · CDNUnited States
AS15169Google LLC
8188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
627--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1444219B1879679C42E6CEA02BBF7B83C4642A83B043379D7C10F2D9D253A4DB9105D57

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Wq9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDys:l9i5Q62I/xE6x4g5bn/d

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12325:EKCMAoYBEJATTJcJmhJBAGAgSqIFWLRMuYCiiMNQ4FCAUPYDFGQ4gBAmAmFqyYwwgJJ2NZgEwgBAHQMgQTwgJ4gkVxAlCEAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00203838383c3c3c
Perceptual Hash:cf3092983831cfcf
Difference Hash:6969616171616161
Wavelet Hash:3c3c3c3c3c3c3c3c
Color Hash:#40931f

Scan History

Scan history not available

Unable to load historical scan data