Security Scan Report: www.vgavoile.org

Site favicon
Submitted: Sep 17, 2026, 11:47:29 PMCompleted: Sep 17, 2026, 11:48:39 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate 6-year-old French sailing club whose WordPress site appears compromised: CRITICAL IDS alerts (EtherHiding exfil, ErrTraffic checkin), blockchain RPC/smart-contract calls, and a ClearFake EK resource mean it now serves hidden malware.

Risk Factors (4)
Critical IDS malware/exploit-kit alerts on a live page (EtherHiding exfil, ErrTraffic checkin)
Blockchain RPC + smart-contract getDomain() calls used to retrieve hidden payloads
Multi-source corroborated ClearFake exploit-kit indicator on a loaded resource
Legitimate 6-year-old WordPress site appears compromised and repurposed to serve malware
Domain age information unavailable

Details

Page Title

VGA Voile – Club de voile à Saint Maur des Fossés

Scan Type

public

Domain Name Analysis

Within the non-profit oriented generic top-level domain (.org), 'www.vgavoile.org' is registered; it also runs on subdomain 'www'. Its registrable label 'vgavoile' stretches across 8 characters split between 4 vowels and 4 consonants. Splitting it apart reveals 2 words: vga, voile. Median word length comes out to 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.vgavoile.org

Page Load Overview

22.19s
Total Load Time
5.7 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr-FR
Text Length:3,445 chars
Detector Agreement:80%

Website Classification

Primary Category

entertainment media97% confidence
Type: spa
Method: ml+structural

All Detected Categories

entertainment media
97%
documentation technical
97%
education learning
70%
blog personal website
68%
travel tourism
48%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
95.135.23.164France
AS16276OVH SAS
9142.251.13.97Google · CDNUnited States
AS15169Google LLC
9104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9216.239.34.36Google · CDNUnited States
AS15169Google LLC
9104.18.10.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
9192.0.77.48San Francisco, California, United States
AS2635Automattic, Inc
728--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18473D712D36448F53A5F8729848AF318F258F680CA4967A7F0BDD15487CD2BA18B7F4E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:M2klxUa8Fv08rg0dV9Fi878QBpPKypy6IZ/9:M2IxUaW08rg0dV9Fi879BpPDa

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:79456:Ab0wAIaKiGlwZZAiCACVNEb8I9kgmAkgwYSSUATCElUJKQuYAJBBACIgEEQAChghoDb4LIm4BpI645AMFYFTQIoJBQgADCCF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffc783c7ffef00
Perceptual Hash:b2cecbc930b04bb6
Difference Hash:2b2e0f0f0f1b0c8f
Wavelet Hash:bfc3838387ebc700
Color Hash:#87a5c5

Scan History

Scan history not available

Unable to load historical scan data