Security Scan Report: bonas.nl

Site favicon
Submitted: Sep 19, 2026, 4:47:28 AMCompleted: Sep 19, 2026, 4:47:56 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate Dutch architecture institute site (23-year-old domain) that appears compromised — it loads two independently flagged malware domains and shows a CRITICAL ET MALWARE EtherHiding exfiltration IDS alert. Visitors risk malware; avoid until cleaned.

Risk Factors
Malicious third-party scripts injected into page (wp inject pattern indicates compromised WordPress)
EtherHiding exfiltration technique detected on outbound network traffic
Multiple distinctly different malicious external domains loaded by a single page
Site serves malware to visitors despite legitimate institutional content
Domain age information unavailable

Details

Page Title

Bonas – Kennisportaal voor Nederlandse architectuur en stedenbouw

Scan Type

public

Domain Name Analysis

You're looking at domain 'bonas.nl' on the Dutch country-code top-level domain (.nl). Its registrable label 'bonas' stretches across 5 characters with 2 vowels and three consonants. Splitting it apart reveals 2 words: bon, as. The median word length lands at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bonas.nl

Page Load Overview

8.78s
Total Load Time
5.2 MB
Total Size

Language Analysis

Primary Language

🇳🇱Dutch
Code: nl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:nl-NL
Text Length:3,512 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning38% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
38%
real estate property
27%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
18188.240.53.40Netherlands
AS20857Signet B.V.
16104.26.4.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
16188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
503--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T124C2B632E18510D37F4E9B3CE2A5E2286298E6105907BBB770F831DC99456FB10F7A5E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:odUqQm0PIlGDzHz8CMe9ihphG3oYqoYFprfWZdSZUaAaXkWuN:omqQmsSGDjAx3YfYF4ZdypdNm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26909:ECwxQAEGUFglogg4BOEhoODiCIZgYYPXXGEQbMA6YAQAWSQFgBk5GZSUxAwAE0CQIVE1AT0CMIBeYqAARCKgTgaR4chAQ0Kg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffdfff838181
Perceptual Hash:bfc038b7c03fc289
Difference Hash:2a17133b232f3b33
Wavelet Hash:ff839f839b838181
Color Hash:#863a2d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data