Security Scan Report: iceido.com

Site favicon
Submitted: Oct 1, 2026, 1:05:12 PMCompleted: Oct 1, 2026, 1:06:40 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Established casino-spam WordPress site compromised with an EtherHiding malware loader: six CRITICAL IDS trojan alerts, blockchain RPC C2 traffic, and multi-feed malware threat-intel on the page URL itself.

Risk Factors (6)
Critical IDS malware (EtherHiding) alerts indicating trojan/loader activity
Primary domain and page URL flagged as malware by multi-feed threat intelligence
Blockchain RPC C2/exfiltration traffic initiated by page scripts
Threat-intel match on third-party resource IP/port with 2 corroborating feeds
Low legitimacy score (15/100) with only domain age as a positive signal
Unranked external JavaScript host (browseid.codes) supplying code to the page
Domain age information unavailable

Details

Page Title

www.iceido.com

Scan Type

public

Domain Name Analysis

The domain 'iceido.com' uses the commercial generic top-level domain (.com) and has no subdomain. The core label 'iceido' covers 6 characters holding four vowels versus 2 consonants. Word splitting yields two words: ice, ido. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://iceido.com/

Page Load Overview

11.08s
Total Load Time
827 KB
Total Size

Language Analysis

Primary Language

🇼🇦CY
Code: cy
Confidence:27%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:62,490 chars
Detector Agreement:33%
Language mismatch: Declared as es but detected as cy

Website Classification

Primary Category

cryptocurrency blockchain95% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
95%
gambling betting
79%
corporate business
68%
government public service
66%
technology software
65%

Detected Features

Search
Articles
Comments

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.219.42.124United States
AS8560IONOS SE
4132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
4178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4150.136.141.142Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.26.5.88Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.66.164.193Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.66.150.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
4711--

Detected Technologies6

WordPressv7.1.2
100%
JQueryv3.7.1
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15B84412302471A7E624D13CE83207A4AE4DB8537FE125C5A77B7DED7AB9BEC18419243

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:ZjwjHYZwHWnJHcxAmIjFVzjsjHRnCuuRZEalY0Iqj28glsoYNjjh:X1xVS4k8glsd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:400645:FhDkiBQhhTmASABMEQjp6FgSlgHpAELgkTBZAVZgAUoJsVV6BgAgABgIOiFqUthUNDAiCAMYACygQBAtQkgSAJAAmSJQ1lGw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffff81818181ff
Perceptual Hash:bf85c47a696bc019
Difference Hash:666d40333b333b3b
Wavelet Hash:60ffff81818181af
Color Hash:#2d8649

Scan History

Scan history not available

Unable to load historical scan data