Security Scan Report: gallowaygrillwarwick.com

Site favicon
Submitted: Sep 22, 2026, 7:47:27 AMCompleted: Sep 22, 2026, 7:48:09 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Legitimate 8-year-old restaurant site appears compromised: page carries a CRITICAL EtherHiding malware IDS alert, loads malware-tagged xaz2.com and a blockchain RPC gateway used for payload delivery. No phishing forms, but the malware-serving behavior makes it unsafe.

Risk Factors (4)
Critical IDS malware/network-trojan alert on the scanned page
Loads a malware-tagged third-party domain (xaz2.com, 2 feeds) and a blockchain RPC gateway consistent with EtherHiding payload delivery
Primary domain tagged as a malware loader (unverified, single source)
Evidence indicates the legitimate restaurant site has likely been compromised / injected with a loader
Domain age information unavailable

Details

Page Title

Galloway Grill – Open seven days for breakfast, lunch, dinner in Warwick NY

Scan Type

public

Domain Name Analysis

The domain 'gallowaygrillwarwick.com' uses the commercial generic top-level domain (.com) and has no subdomain. Count 20 characters in 'gallowaygrillwarwick' containing 6 vowels alongside 14 consonants. Tokenizing the label suggests 3 words: galloway, grill, warwick. Expect 7 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://gallowaygrillwarwick.com

Page Load Overview

3.95s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:5,536 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing64% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

download file sharing
64%
phishing scam
63%
social media network
59%
finance banking
54%
cryptocurrency blockchain
51%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1074.208.236.142United States
AS8560IONOS SE
3142.251.14.97Google · CDNUnited States
AS15169Google LLC
313.33.187.25Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
335.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
313.33.187.28Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
3188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3216.239.34.36Google · CDNUnited States
AS15169Google LLC
313.33.187.110Cloudfront · CDNNew York, New York, United States
AS16509Amazon.com, Inc.
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
349--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T175C2C631E19000E23E9F9B7CB2A2F2386598EA10991677B770FD31DC59555FB00A7A2F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:D9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyf/8pre7kZdSZUaAaXkWra:D9i5Q62I/xE6x4g5bn/zBZdypdNra

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:26535:JjgBFiWwDMASKFFwoV1AwUQBmGwASNCoQx4EDEsEKiWSITSEZICFoAWEukAgEEABYSISCMLBBEiAGjDKYAMAJBDqQACrAASB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffff0301000000cf
Perceptual Hash:a8c7fed2f229a812
Difference Hash:4179f397dcb39f3f
Wavelet Hash:ffff0f03040001ff
Color Hash:#d22d69

Scan History

Scan history not available

Unable to load historical scan data