Security Scan Report: rewards-justlend.org

Submitted: Sep 25, 2026, 4:14:27 PMCompleted: Sep 25, 2026, 4:15:02 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Fake 'JustLend DAO Compounding Crates' rewards site on a 7-day-old lookalike domain funnels users to wallet connects while a CRITICAL EtherHiding malware IDS alert fires — a classic wallet-drainer scam.

Risk Factors
Impersonation of JustLend DAO on a mismatched, 7-day-old domain
Crypto wallet-connect funnel (drainer/approval-phishing pattern)
CRITICAL IDS malware alert (EtherHiding Exfil M2)
Blockchain RPC/smart-chain connections tied to a fake rewards page
Unranked domain pushing time-pressured 'register for the snapshot' reward claims
Domain age information unavailable

Details

Page Title

JustLend DAO · Compounding Crates

Scan Type

public

Domain Name Analysis

Within the non-profit oriented generic top-level domain (.org), 'rewards-justlend.org' is registered and has no subdomain. The second-level label 'rewards-justlend' is 16 characters long split between four vowels and eleven consonants, notching 1 hyphen. Segmentation suggests three words: rewards, just, lend. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rewards-justlend.org/compounding-crates

Page Load Overview

2.39s
Total Load Time
3.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,709 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency60% confidence
Type: static
Method: structural

All Detected Categories

cryptocurrency
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5196.251.107.235Germany
AS214351Femo It Solutions Limited
3142.251.13.95Google · CDNUnited States
AS15169Google LLC
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
33.161.82.42Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
3108.131.74.31Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
237--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E014BF32531A17ABE42F46F4474B1A0E3D9E644BDE8246CD7A8D85EC8FDEBF9D542800

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:YoghVvcxTfUbtKEJRtr2VvFhkt3N0oZr/rk9:YognExzUJntcFE0oZr/rk9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:200469:BGJ6WIAJkOAIDJAvBQCDBCE+AocAGARCjIASAhOoluDoEiC1gfmoCAAJKzEpq4QEOJRIHsMQQhDE9PQaE6DREWoUWgjGBohC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:341e1e0c00342460
Perceptual Hash:929d65627a96a43d
Difference Hash:6d7a3e3d19c5c5d1
Wavelet Hash:051f1f0d09777571
Color Hash:#53ac93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data