Security Scan Report: robera.fr

Site favicon
Submitted: Sep 14, 2026, 4:47:29 AMCompleted: Sep 14, 2026, 4:48:17 AMpubliccompleted

Summary

This website contacted 28 IPs in 4 countries across 21 domains to perform 1 HTTP transaction. The main domain is robera.fr and was registered 18 years ago.

Submitted URL: https://robera.fr

AI Security Verdict

High Risk

Confidence: 75%

8
Risk Score

Genuine-looking golf retailer, but threat-intel flags the domain as a malware loader and network IDS detects CRITICAL EtherHiding exfiltration — site appears compromised to distribute/hide malware.

Risk Factors
Primary domain reported as a malware loader
Third-party domain loaded by the page (xaz2.com) reported as malware by two independent feeds
CRITICAL network IDS hit for EtherHiding exfiltration (malware/trojan activity)
Ethereum RPC endpoint (0xrpc.io) contacted — consistent with blockchain-abused malware infrastructure
Indicator of compromise on the primary domain of the scanned page
Domain age information unavailable

Details

Page Title

ROBERA.fr - LE chariot de golf SUIVEUR ultime.

Scan Type

public

Language

🇫🇷

French

(80% confidence)

Category

corporate

(50%)

Domain Information

Within the French country-code top-level domain (.fr), 'robera.fr' is registered with no subdomain. The core label 'robera' covers 6 characters containing 3 vowels alongside three consonants. Word splitting yields two words: rob, era. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://robera.fr

Page Load Overview

5.23s
Total Load Time
76
HTTP Requests
21
Domains
4.5 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:fr-FR
Text Length:6,927 chars
Detector Agreement:80%

Website Classification

Primary Category

corporate50% confidence
Type: spa
Method: structural

All Detected Categories

corporate
50%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
22192.0.76.3San Francisco, California, United States
AS2635Automattic, Inc
2217.160.0.153Germany
AS8560IONOS SE
2142.251.20.97Google · CDNUnited States
AS15169Google LLC
2142.251.153.4Google · CDNUnited States
AS15169Google LLC
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.94Google · CDNUnited States
AS15169Google LLC
2142.251.127.148Google · CDNUnited States
AS15169Google LLC
2142.251.150.4Google · CDNUnited States
AS15169Google LLC
2142.251.127.155Google · CDNUnited States
AS15169Google LLC
2216.239.34.36Google · CDNUnited States
AS15169Google LLC
7628--

Page Statistics

76
Requests
21
Unique Domains
4.7 MB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B9621972834A6DC52E6CD601BBF7B46C820AEC3B5432ADD7C14F1E5E24A64EB5006D77

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:K59fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDyahluMG/mp7:K59i5Q62I/xE6x4g5bn/1mMG/mF

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15199:MQpMWw8AAiAUApBRhFQIYsAUtQChIgUIkgzgiJiHRQHQKVmggkhxhwERHIOJWDBIRPLSwKkl9GMQkDYaQEAAKIUIJhgpEISo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fff0000000000000
Perceptual Hash:eac9cdcdc590b0b2
Difference Hash:1311050105050505
Wavelet Hash:ffff313101010101
Color Hash:#40bf64

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data