Security Scan Report: reuxen.pt

Site favicon
Submitted: Sep 14, 2026, 10:47:27 AMCompleted: Sep 14, 2026, 10:48:06 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 90%

9
Risk Score

Legitimate-looking Portuguese pharma site (Reuxen/Tecnifar) that appears compromised: CRITICAL EtherHiding malware IDS alerts, blockchain C2 contact, and a loaded exploit-kit resource flagged by 3 feeds.

Risk Factors
CRITICAL network IDS alerts indicating EtherHiding malware exfiltration
Loaded third-party domain (ultraspeed.pro) identified as an exploit kit by 3 independent feeds
Blockchain RPC endpoint contacted, matching EtherHiding C2 pattern
Primary domain carries an unverified malware threat-intel tag
Domain age information unavailable

Details

Page Title

Reuxen – Não há dor que me pare

Scan Type

public

Domain Name Analysis

Within the Portuguese country-code top-level domain (.pt), 'reuxen.pt' is registered with no subdomain. The second-level label 'reuxen' is 6 characters long with 3 vowels and three consonants. Splitting it apart reveals two words: reu, xen. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://reuxen.pt

Page Load Overview

2.95s
Total Load Time
2.5 MB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-PT
Text Length:6,029 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: spa
Method: structural

All Detected Categories

No categories detected

Detected Features

Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17188.166.155.58Slough, England, United Kingdom
AS14061DigitalOcean, LLC
3192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
3142.251.13.97Google · CDNUnited States
AS15169Google LLC
3172.217.208.95Google · CDNUnited States
AS15169Google LLC
3192.0.77.2San Francisco, California, United States
AS2635Automattic, Inc
3151.101.193.229Fastly · CDNUnited States
AS54113Fastly, Inc.
374.125.29.95Google · CDNUnited States
AS15169Google LLC
3104.21.6.137Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3192.178.183.94Google · CDNUnited States
AS15169Google LLC
3216.239.32.36Google · CDNUnited States
AS15169Google LLC
5915--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15CA2F931F0A80015BB5FABEDD1ABB32CE568B6509F4197B670F420588578AF710B771D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:+zmrjooZ0WDX6880a3GL2Pr/ZdSZUaArkW35pANXRngfW:mmrjooZ0WDXy0a39DZdypGKXRgfW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22676:OVJ5TBMGIAgAhQJgqkAgPcNmKwLgqgkAki7eEgAOBCwAETiLEoQDcEyKYTUK8KK+h0BBCgUyBDOE8phmDFAQAAoFCEQgQVKF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefeffffffffffff
Perceptual Hash:d5555555a8aaaaaa
Difference Hash:0000000000000000
Wavelet Hash:0e0e0e0e0e0e0e0e
Color Hash:#e0a66c

Other Hashes

Crop Resistant:0000000000000000

Scan History

Scan history not available

Unable to load historical scan data