Security Scan Report: 360bayern.de

Redirected to:
https://www.360bayern.de/
Site favicon
Submitted: Sep 23, 2026, 6:47:35 AMCompleted: Sep 23, 2026, 6:48:29 AMpubliccompleted

This website contacted 4 IPs in 4 countries across 5 domains to perform 97 HTTP transactions. The main domain is 360bayern.de and was registered 4 weeks ago.

Submitted URL: https://360bayern.de

Effective URL:

https://www.360bayern.de/
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Real self-branded German virtual-tour business whose page loads malware-tagged xaz2.com and communicates with an Ethereum RPC endpoint under a CRITICAL EtherHiding malware IDS alert — likely compromised; avoid interaction.

Risk Factors (4)
Critical IDS malware alert (EtherHiding Exfil)
Charging/communication with Ethereum RPC endpoint 0xrpc.io
Malware-tagged third-party domain xaz2.com loaded on the page
Very new domain (19 days) with no reputation
Domain age information unavailable

Details

Page Title

Virtuelle Touren (360°-Rundgänge) - 360bayern.de: Online-Marketing optimieren mit Virtuellen Touren in Premium-Qualität!

Scan Type

public

Domain Name Analysis

Within the German country-code top-level domain (.de), '360bayern.de' is registered and has no subdomain. The registrable portion '360bayern' spans 9 characters holding 2 vowels versus four consonants; bonus characters include 3 digits. Breaking it apart gives two words: 360, bayern. Expect 4.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://360bayern.de

Page Load Overview

18.39s
Total Load Time
4.7 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:8,228 chars
Detector Agreement:80%

Website Classification

Primary Category

documentation technical68% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
68%
technology software
53%
government public service
35%
corporate
25%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2565.21.92.44Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
24146.19.24.104Poland
AS201814MEVSPACE sp. z o.o.
24188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
24185.68.16.72Ukraine
AS200000Hosting Ukraine LTD
974--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T148721A7282556CD41B9DDB91BBB7B52C430AE42F4132A9D7C30E1E9C28397DB7201E67

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:I9fNwMKDfNQ62Ho/xE6x4aUg/5j/nfnDy5ElEbdQPPXz+DFo:I9i5Q62I/xE6x4g5bn/YEGqCDFo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:16448:Jk+EQoEDEQQMBAQzmEIAVKqoE0igVeKogOIBbKsgO0NlAI8ZACgHhoTAEBKpAUES6AEITLghIVzAKIUCQAIAMAgYZjCVQCjW

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff00000000ffffff
Perceptual Hash:a25abdd8a4f4ca25
Difference Hash:33c9cdcdc7090707
Wavelet Hash:ff00000000ffffff
Color Hash:#931f6f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data