Security Scan Report: motherload.me

Site favicon
Submitted: Sep 30, 2026, 1:47:29 AMCompleted: Sep 30, 2026, 1:48:30 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

ClearFake/EtherHiding malware: primary-domain ClearFake Indicator of Compromise, 3 CRITICAL EtherHiding-exfil IDS alerts, blockchain-RPC payload staging, and a multi-source 'ek clearfake' host, behind a fake HUVIP gambling brand.

Risk Factors (6)
ClearFake malware-family Indicator of Compromise on the primary domain
CRITICAL IDS malware alerts for EtherHiding exfiltration (x3)
Obfuscated on-chain payload retrieval via multiple Polygon RPC endpoints and getDomain() contract calls
Multi-source malicious-host Indicator of Compromise on a loaded resource (ek clearfake)
Brand claim mismatch: claims to be the official HUVIP site (huvip.tech) on a different 42-day-old domain
New domain (42 days) plus unranked reputation
Domain age information unavailable

Details

Page Title

HUVIP motherload ⭐️ Link Đăng Ký/ Đăng Nhập HUVIP【2026】secondary capture

Scan Type

public

Domain Name Analysis

You're looking at domain 'motherload.me' on the Montenegrin country-code top-level domain (.me) while skipping any subdomain. Its registrable label 'motherload' stretches across 10 characters split between 4 vowels and six consonants. Breaking it apart gives two words: mother, load. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://motherload.me

Page Load Overview

8.34s
Total Load Time
4.4 MB
Total Size

Language Analysis

Primary Language

🇻🇳Vietnamese
Code: vi
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:vi
Text Length:9,304 chars
Detector Agreement:100%

Website Classification

Primary Category

gambling betting95% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

gambling betting
95%
entertainment media
81%
technology software
76%
corporate
35%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7142.251.13.97Google · CDNUnited States
AS15169Google LLC
7142.251.127.84Google · CDNUnited States
AS15169Google LLC
7216.239.34.36Google · CDNUnited States
AS15169Google LLC
7104.26.3.238Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
7216.239.32.36Google · CDNUnited States
AS15169Google LLC
7410--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T113933B7362416027236746EDD059370D66DAE00BEE068A9DB3F815EDDED9CF22232B4D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:h4W3rIyp55ticYrl+ZTEhIjjtth+gMi5UevweYge8SoFnAKqe+2otrF:h4W39/5n+l+ZTEhIjjtP+g95UevweYg6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:97573:wIJILQIxISpIYAYAUA9A6KLouoJCPAShBGSAE5OJmFZwgGUB0nQhHpASEgBSrRR2gQMohFQaw4IFkBhFYgBUE9oIAaBEgJBP

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1c1818183c3c3c3c
Perceptual Hash:cc38b696329c9e36
Difference Hash:3c323070e8f0e0c8
Wavelet Hash:ff18183c3c3c3c3c
Color Hash:#783a55

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data