Security Scan Report: noticiasaltiempo.com

Site favicon
Submitted: Sep 22, 2026, 11:47:25 AMCompleted: Sep 22, 2026, 11:48:17 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate 12-year-old Dominican news site, but network IDS shows CRITICAL EtherHiding malware exfiltration plus blockchain RPC loader behaviour and eval/Function obfuscation — likely compromised and serving a malicious loader.

Risk Factors (5)
CRITICAL network IDS alert: ET MALWARE EtherHiding Exfil M2 (x3)
HIGH network IDS alert: ET DROP Spamhaus DROP Listed Traffic Inbound
Page loads blockchain smart-chain RPC endpoints and issues an Ethereum contract getDomain() request
Heavy JS obfuscation (eval/Function construction) on an otherwise content-driven news site
Malicious third-party CDN (entry-code-cdn.codes) linked to the page and reported by multiple feeds
Domain age information unavailable

Details

Page Title

Inicio - Noticias al tiempo

Scan Type

public

Domain Name Analysis

The domain 'noticiasaltiempo.com' uses the commercial generic top-level domain (.com) with no subdomain. The core label 'noticiasaltiempo' covers 16 characters holding 8 vowels versus 8 consonants. Segmentation suggests 3 words: noticias, al, tiempo. Median word length is six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://noticiasaltiempo.com

Page Load Overview

11.62s
Total Load Time
4.7 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:10,121 chars
Detector Agreement:75%

Website Classification

Primary Category

forum community discussion79% confidence
Type: spa
Method: ml+structural

All Detected Categories

forum community discussion
79%
government public service
62%
documentation technical
53%
news media journalism
52%
entertainment media
36%

Detected Features

Login Form
Comments
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8172.217.208.95Google · CDNUnited States
AS15169Google LLC
8192.178.183.97Google · CDNUnited States
AS15169Google LLC
8188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8142.251.14.94Google · CDNUnited States
AS15169Google LLC
8216.239.34.36Google · CDNUnited States
AS15169Google LLC
8142.251.127.155Google · CDNUnited States
AS15169Google LLC
8142.251.110.94Google · CDNUnited States
AS15169Google LLC
8172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8142.251.153.4Google · CDNUnited States
AS15169Google LLC
10012--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D1829672A0540A677F5E97FCC1D2B229F459A701DA12ABB670F421184ED8AF700F761D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:k3I4M2E524MXWySCN7GuX2+4r/ZdSZUaAvHkWRuN:8biVZdypi9Rm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18042:ZCIEIKxgBFm0gAoTFkIERAdBhJcEOgA4IJpxJGRRaQOAkagSdD9SDx0ARig5agAgAhEMJQBokotAQERYwWgTKBBfACwECIoO

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00fffff9fbf98981
Perceptual Hash:bb443f483b493536
Difference Hash:8268070303133b3b
Wavelet Hash:0081fff9f9f98181
Color Hash:#78583a

Scan History

Scan history not available

Unable to load historical scan data