Security Scan Report: 18.208.215.155

Site favicon
Submitted: Oct 1, 2026, 1:04:52 PMCompleted: Oct 1, 2026, 1:05:55 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Compromised/weaponized page running the ErrTraffic/Exvicy ClickFix loader with EtherHiding exfiltration and wallet-drainer RPC calls; malicious kit confirmed — do not interact.

Risk Factors (5)
Known malicious ClickFix/ErrTraffic loader injected in the page body
Critical-network IDS alerts for EtherHiding exfiltration (17x) and Spamhaus DROP traffic
Page loads scripts from unranked, threat-flagged third-party hosts (lovezramexar.info, browseid.codes, makeverizyjar.info)
Blockchain RPC connections combined with 'Foundation' branding — wallet-drainer/approval-phishing pattern
Page served from a bare IP address (18.208.215.155) with page title having no relation to the host — new/unranked infrastructure
Domain age information unavailable

Details

Page Title

Rangaah-Ndi Foundation

Scan Type

public

Domain Name Analysis

Within an unknown top-level domain, '18.208.215.155' is registered and has no subdomain. Count 14 characters in '18.208.215.155' holding 0 vowels versus 0 consonants, plus 11 digits. Breaking it apart gives 4 words: 18, 208, 215, 155. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://18.208.215.155/

Page Load Overview

23.54s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:2,182 chars
Detector Agreement:75%

Website Classification

Primary Category

education learning80% confidence
Type: spa
Method: ml+structural

All Detected Categories

education learning
80%
government public service
64%
social_media
25%
forum
25%
news/blog
20%

Detected Features

Search
Articles
Comments

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
718.208.215.155Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
7172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
7152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
7104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
735.227.193.242Google · CDNKansas City, Missouri, United States
AS396982Google LLC
7178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
7158.94.208.87Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
10515--

Detected Technologies7

WordPressv6.8.10
100%
JQueryv3.7.1
100%
50%
20%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T113E3E97039861935111F16CFA047220EA4D7CEF5E922A5F1F5FF4328ABB4C9036EA976

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:KAOH94I6uCHhVd0WVkjhDNfbIXLk1soTXBPSQrbLQq:q6uCHhV8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:146950:BouDBYARwgCHIChEegSAgBRhSBAV+DSpRDd4obJIodZFZCAAgoCGEALakoMyqkSAYEOAIqwAxByaARsAIKIBqkAQiPEAAAFg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0000000000ffff
Perceptual Hash:8a1cb73e9c9f0c86
Difference Hash:2b04313131b10d08
Wavelet Hash:ff0018191800ffff
Color Hash:#7ad22d

Other Hashes

Crop Resistant:2b04313131b10d08

Scan History

Scan history not available

Unable to load historical scan data