Security Scan Report: drgift.eu

Site favicon
Submitted: Oct 1, 2026, 1:04:34 PMCompleted: Oct 1, 2026, 1:06:03 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Newly registered gift-shop domain that fired 5 CRITICAL 'ET MALWARE EtherHiding Exfil' IDS alerts and opens several blockchain RPC channels with no legitimate web3 use, matching an exploit-kit IP — strong malware-injection signal. Avoid.

Risk Factors (6)
Critical IDS malware alert (EtherHiding exfiltration) — known malware delivery/exfiltration technique
Multiple blockchain RPC/JSON-RPC connections on a site with no legitimate web3 purpose (wallet-drainer/EtherHiding pattern)
IP flagged as an exploit-kit host ('ek clearfake') by two feeds
Domain registered ≤1 day ago
Unranked third-party script host (browseid.codes) injecting code
Meta og:title claims 'Dalina Gift Basket Store' while the site is branded 'Dr. Gift' on drgift.eu
Domain age information unavailable

Details

Page Title

Dr. Gift - Personalized Gifts for Every Occasion

Scan Type

public

Domain Name Analysis

The domain 'drgift.eu' uses the .eu country-code top-level domain while skipping any subdomain. The second-level label 'drgift' is 6 characters long split between 1 vowel and 5 consonants. Breaking it apart gives two words: dr, gift. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://drgift.eu/

Page Load Overview

21.69s
Total Load Time
22.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:9,190 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate70% confidence
Type: spa
Method: structural

All Detected Categories

corporate
70%
e-commerce
40%

Detected Features

Products
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2280.240.26.232Frankfurt am Main, Hesse, Germany
AS20473The Constant Company, LLC
1174.125.29.95Google · CDNUnited States
AS15169Google LLC
11142.251.127.97Google · CDNUnited States
AS15169Google LLC
11172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11142.251.110.94Google · CDNUnited States
AS15169Google LLC
11188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11216.239.34.36Google · CDNUnited States
AS15169Google LLC
11142.251.127.154Google · CDNUnited States
AS15169Google LLC
11142.251.14.94Google · CDNUnited States
AS15169Google LLC
11178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
19817--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16594E673B076187A012F72DA9067274EA4E7C75BD6070BF4F2BA92AC83D5C943E53249

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:0caYI/mRKcaQJIXzSl6F2r6CjAvDGEgUCXuypXO:na6atSl6F2r6CjAvDGEgUCXud

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:415988:YjlkZACDSEQKoZDAeSBiNJToIgoiIEC+gxBuAkgAshaAxzDkRIOQBEKUOsxGSxQAoMwCkBNRiIRSyMAwAJGYNSKlgLdAh2gq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Scan History

Scan history not available

Unable to load historical scan data