Security Scan Report: zarintandis.ir

Submitted: Sep 17, 2026, 2:47:47 PMCompleted: Sep 17, 2026, 2:50:09 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 65%

7
Risk Score

Legitimate-looking 14-year-old WooCommerce store, but its primary domain carries a single-source Gootloader malware indicator — consistent with a compromised site. Avoid submitting credentials until cleared.

Risk Factors (3)
Content-malware indicator of compromise (Gootloader) matched to the primary scanned domain
WordPress/WooCommerce login and search forms present (one password field)
Site classified partly as adult content (32%) by ML classifier, low-confidence signal
Domain age information unavailable

Details

Page Title

فروشگاه اینترنتی زرین تندیس – زرین تندیس

Scan Type

public

Domain Name Analysis

The domain name 'zarintandis.ir' uses the Iranian country-code top-level domain (.ir) and has no subdomain. Its registrable label 'zarintandis' stretches across 11 characters split between four vowels and 7 consonants. It segments into 5 words: zar, in, t, and, is. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zarintandis.ir

Page Load Overview

75.20s
Total Load Time
6.9 MB
Total Size

Language Analysis

Primary Language

🇮🇷Persian
Code: fa
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:fa-IR
Text Length:13,387 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media70% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
70%
e-commerce shopping
53%
adult content
32%
social_media
25%
e-commerce
20%

Detected Features

Login Form
Articles
Products

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
69185.37.54.10Iran
AS48434Tebyan-e-Noor Cultural-Artistic Institute
69212.16.67.4Iran
AS34837Institute for Research in Fundamental Sciences
69142.251.13.97Google · CDNUnited States
AS15169Google LLC
2073--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B042C4FB682B654E63A13BDDD182731CD249946F8BF40765ECAC062D62FD7EC200AE45

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:vnCOp72VPk1gtXDHT0Vms9n3nvwhyju/+ngLXyRcKtRiN:bp72FL4Vn3nvwhyju/+niyTGN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:13153:IoAERQKoYyaygHPQRgABscILMgrk5ERrQBAEgJJVGIAlAAIhjCQQEhKRVH4ANUMJTyAYYBAkF0QAAaYMQMdcBCBjgEkAAmIB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:4020c1c1f7fffffe
Perceptual Hash:ed6992927429e9c9
Difference Hash:90c203070771612c
Wavelet Hash:4000c1c1f7ffffc0
Color Hash:#bc79d2

Scan History

Scan history not available

Unable to load historical scan data