Security Scan Report: goatcheese.me

Submitted: Sep 17, 2026, 1:47:31 PMCompleted: Sep 17, 2026, 1:49:06 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate goat-farming WordPress blog, but compromised: critical EtherHiding malware IDS alert, blockchain RPC calls, and malware-flagged third-party resources. Do not interact.

Risk Factors
Critical IDS malware alert (EtherHiding exfiltration) on this page
Primary domain flagged as malware loader in threat intelligence
External malware resources loaded (xaz2.com iclickfix, framtidabruk.com)
Blockchain RPC domain contact consistent with EtherHiding C2/payload retrieval
Signs of WordPress compromise on an otherwise legitimate blog
Domain age information unavailable

Details

Page Title

Goatcheese Me! – Cheese Please

Scan Type

public

Domain Name Analysis

The domain 'goatcheese.me' uses the Montenegrin country-code top-level domain (.me). Count 10 characters in 'goatcheese' containing 5 vowels alongside 5 consonants. Splitting it apart reveals 2 words: goat, cheese. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://goatcheese.me

Page Load Overview

75.29s
Total Load Time
345 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:34%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:sv-SE
Text Length:7,098 chars
Detector Agreement:75%
Language mismatch: Declared as sv-SE but detected as en

Website Classification

Primary Category

social media network26% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

social media network
26%

Detected Features

Search
Articles
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10109.228.165.33Karlshamn, Blekinge County, Sweden
AS8473Bahnhof AB
5142.251.14.95Google · CDNUnited States
AS15169Google LLC
5192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
554.174.31.150Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
5172.217.208.95Google · CDNUnited States
AS15169Google LLC
535.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
5188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.110.94Google · CDNUnited States
AS15169Google LLC
458--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CB13F771D35E10927F1E871C66A4B2E4566CA224DC022FBBB878B178518C4EB05BFB5F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:79i5Q62I/xE6x4g5bn/+DWgZdypw+kAijGY1axgz:5iC7DHyp7ijG4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:42983:AtjEQHIgAXkMokIHAAQWUAEFAg9YAwKEKoCJpWAqgwjgFQEzKCirwO1oAAAtCUCkKC+QDBgYogQwgRDgQAASmGaPhiCINACC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000ffffffffffff
Perceptual Hash:b6361616363696dc
Difference Hash:6d25002602000000
Wavelet Hash:00008882fafefefe
Color Hash:#aad279

Scan History

Scan history not available

Unable to load historical scan data