Security Scan Report: wordpresshjalp.se

Submitted: Oct 1, 2026, 4:27:47 PMCompleted: Oct 1, 2026, 4:28:28 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 90%

8
Risk Score

Established Swedish WordPress-help site compromised and serving the ClearFake ClickFix malware chain (CRITICAL + HIGH YARA hits) alongside injected casino SEO spam; do not visit.

Risk Factors (4)
ClearFake malware/ClickFix loader injected into the page (CRITICAL YARA, roster-anchored)
Second ClearFake script present that blocks navigation and removes rival kits (HIGH YARA, roster-anchored)
Page is a compromised WordPress installation repurposed with casino/gambling SEO spam content and outbound links to unrelated casino domains
Obfuscated/encoded inline JavaScript with encoding-decoding routines
Domain age information unavailable

Details

Page Title

Wordpresshjälp - När du får problem med Wordpress

Scan Type

public

Domain Name Analysis

You're looking at domain 'wordpresshjalp.se' on the Swedish country-code top-level domain (.se) without a subdomain. The core label 'wordpresshjalp' covers 14 characters with three vowels and 11 consonants. Tokenizing the label suggests three words: wordpress, hj, alp. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://wordpresshjalp.se/

Page Load Overview

3.41s
Total Load Time
420 KB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:sv-SE
Text Length:5,026 chars
Detector Agreement:50%

Website Classification

Primary Category

gambling betting99% confidence
Type: spa
Method: ml+structural

All Detected Categories

gambling betting
99%
corporate business
90%
technology software
63%
phishing scam
60%
adult content
49%

Detected Features

Search
Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1265.21.122.251Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
12142.251.110.95Google · CDNUnited States
AS15169Google LLC
12142.250.154.94Google · CDNUnited States
AS15169Google LLC
12142.251.20.94Google · CDNUnited States
AS15169Google LLC
484--

Detected Technologies6

WordPressv7.1.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D041970BB541D75222B03BEE4A7FA0855798523DA0D5AF9F8FFD08885C2FD221B161E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:GZNVAw9pc+SN+W2a55UVGg/GlRW3Tfo3VLGz0Jo:Lw9O+SN4VD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:177506:EHoh2woBUAHAiIkAHgSQAVIIGgiJJ1aAUDghkHoTbFikApwFkkhhAiQQcAPgDQYbB1gOgAoEE0D0xrZQBiEiAFEXyT0KKAcE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff8283db8b87df87
Perceptual Hash:b9c5d0c7c9c23ac6
Difference Hash:423a2a333a3a1c3c
Wavelet Hash:ff8081b98981bf87
Color Hash:#d23d2d

Other Hashes

Crop Resistant:423a2a333a3a1c3c

Scan History

Scan history not available

Unable to load historical scan data