Security Scan Report: simelicuir.fr

Site favicon
Submitted: Oct 3, 2026, 4:25:10 AMCompleted: Oct 3, 2026, 4:25:50 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Legitimate 5-year-old French leather-craft site is compromised and now serves a ClickFix kit: a fake Cloudflare 'Human Verification' overlay telling Windows users to paste into Terminal, plus Macfinger AMOS stealer loaders (2 CRITICAL YARA hits, multiple CRITICAL IDS malware alerts). Do not interact.

Risk Factors (6)
Injected ClickFix malware kit on a site whose real content is handmade leather goods (compromised site)
Fake 'Human Verification' overlay impersonating Cloudflare, instructing Terminal paste-and-run
CRITICAL YARA stealer/phishing matches plus roster-anchored known malicious kits
Network IDS CRITICAL malware/C2 alerts (AMOS ClickFix loader, EtherHiding exfiltration)
Unranked third-party script host vale-quaeum-a4hc9.top contacted via sendBeacon; blockchain RPC endpoints loaded by page scripts
Threat-intel report against the primary domain simelicuir.fr (misp.scanmalware.com, single-source 'iclickfix')
Domain age information unavailable

Details

Page Title

Simeli Cuir

Scan Type

public

Domain Name Analysis

Domain 'simelicuir.fr' uses the French country-code top-level domain (.fr) while skipping any subdomain. The registrable portion 'simelicuir' spans 10 characters containing five vowels alongside 5 consonants. Splitting it apart reveals 4 words: sim, eli, cui, r. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://simelicuir.fr/

Page Load Overview

4.91s
Total Load Time
861 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr-FR
Text Length:4,386 chars
Detector Agreement:67%

Website Classification

Primary Category

adult content75% confidence
Type: spa
Method: ml+structural

All Detected Categories

adult content
75%
healthcare medical
32%
government public service
30%

Detected Features

Products

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10193.203.239.46France
AS210403Groupe LWS SARL
7142.251.110.95Google · CDNUnited States
AS15169Google LLC
777.221.153.211Paris, Île-de-France, France
AS210644Aeza Group LLC
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
7142.251.14.94Google · CDNUnited States
AS15169Google LLC
7157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
7178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
7152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
669--

Detected Technologies8

WordPressv7.0.2
100%
JQueryv3.7.1
100%
Bootstrapv4.18.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D58309B3E02D58AA136F43CEB055BBCFB8E39016CAD145B0BBA9835967D1DC1722721D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:KC6klt8ADabAKAV8NAbAUzkT/Sfuwu7u/uWuWuDuuuQuBuYuUu2uNuFu7uOqD3Uu:d6kb8ADiAKAV0AbAHKaqD3edZYo7upgq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:88371:QSBCABwVDKCxrOgkDICgBEDkg8FxfgMHVhFoBRBoCMOUCsRVQUsBJpQJAPIOgdUYUEIIEYAIgYsA1CAoIlhBY0zRyTgAQRiB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffebc1c1
Perceptual Hash:e19e611996699e65
Difference Hash:aa0a000e0c1b5347
Wavelet Hash:00e6fee6e7c1c1c1
Color Hash:#931f67

Scan History

Scan history not available

Unable to load historical scan data