Security Scan Report: diplomatmontessori.co.za

Site favicon
Submitted: Sep 15, 2026, 8:47:27 AMCompleted: Sep 15, 2026, 8:48:04 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Legitimate 11-year-old Montessori school site appears compromised: injected fake 'Human Verification' ClickFix flow plus blockchain EtherHiding/exfil RPC traffic and exploit-kit check-ins (6 CRITICAL IDS). Do not proceed or run any commands.

Risk Factors (5)
Fake CAPTCHA / 'Human Verification' coaching users to open Terminal or paste commands (ClickFix)
EtherHiding malware exfiltration over blockchain RPC endpoints
Exploit-kit check-in ('ErrTraffic Beer Cluster')
Content-injection/malicious scripts on a legitimate school site (compromised)
Runtime code generation via Function() constructor
Domain age information unavailable

Details

Page Title

HOME | Diplomat Monstessori

Scan Type

public

Domain Name Analysis

Domain 'diplomatmontessori.co.za' uses the South African country-code top-level domain (.co.za). Its registrable label 'diplomatmontessori' stretches across 18 characters holding 7 vowels versus eleven consonants. It segments into two words: diplomat, montessori. Median word length comes out to nine characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://diplomatmontessori.co.za

Page Load Overview

16.99s
Total Load Time
2.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:5,822 chars
Detector Agreement:100%

Website Classification

Primary Category

education learning60% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
60%
corporate
35%
phishing scam
33%
government public service
30%
blog personal website
28%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14208.97.186.65Ashburn, Virginia, United States
AS26347New Dream Network, LLC
12142.251.14.95Google · CDNUnited States
AS15169Google LLC
12178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
12188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
12150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
12142.251.110.94Google · CDNUnited States
AS15169Google LLC
12152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
12142.251.20.95Google · CDNUnited States
AS15169Google LLC
12104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1109--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T130B2C772B06A05167B2F93D9C38B723DCA98A582C644AB3570F8601C9BF4FF212A751D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:3pA3iKp+En+Z55Xj2oqNrqwRXdSZsTaAh51TNslQCfEGHRmy4kWDKTa7sZBUKVg6:a3ixEn+Z55Xj2owr/ZdSZUaAhHkWiLN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24623:CNiJRGMysImseNodBMECJEGBoAICIepxgRsI0nhoI0JAAYQkETkEowLA9wLQGmwIEgRQIWkIEAGxEwnUsGASWvG1OlgmJUwC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00f3e3f3e3e3e3f3
Perceptual Hash:e41b1a1b1b1a1b6f
Difference Hash:c706460606060606
Wavelet Hash:00e2e2e3e3e3e3e2
Color Hash:#78443a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data