Security Scan Report: pub-659a914c53f4432eb4a60ed22cdfe264.r2.dev

Submitted: Sep 30, 2026, 12:55:02 AMCompleted: Sep 30, 2026, 12:55:37 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake 'Webmail' login hosted on a Cloudflare R2 bucket that posts the entered email and password cross-origin to 319198.ru.com — a credential phishing page. Do not enter any credentials.

Risk Factors (5)
Cross-origin credential form posting email + password to 319198.ru.com
Credential harvesting on a public cloud-storage bucket URL
Generic webmail login page used as a lure with no legitimate owner
Domain is unranked in Cisco Umbrella top 1M; bucket age is not attributable to this page (shared-hosting tenant, effectively unknown age)
Right-click / context-menu blocking to hinder inspection
Domain age information unavailable

Details

Page Title

Login, Sign in | Webmail

Scan Type

public

Domain Name Analysis

You're looking at domain 'pub-659a914c53f4432eb4a60ed22cdfe264.r2.dev' on the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-659a914c53f4432eb4a60ed22cdfe264'. Its registrable label 'r2' stretches across 2 characters holding 0 vowels versus 1 consonant; bonus characters include one digit. Tokenizing the label suggests two words: r, 2. Average segment length settles at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-659a914c53f4432eb4a60ed22cdfe264.r2.dev/zecto.html

Page Load Overview

0.84s
Total Load Time
180 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:216 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content70% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

adult content
70%
corporate business
50%
technology software
44%
finance banking
36%
documentation technical
28%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1142.251.110.95Google · CDNUnited States
AS15169Google LLC
1104.18.35.32Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.203.64Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.110.94Google · CDNUnited States
AS15169Google LLC
1172.64.152.224Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
87--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D1A2944D75730CAEE823A02BF69F7308E290DE07F68DE9647AAD45845F81C58E19778C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:q8FNiRFsA+gDYST+B3argOyCn78eSgn9jGileY2e:q8FNiRFsrgpT+34gYCAkifZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22530:SdArCIEqgA4VjLEoRANAcsoia4omERMDkrkk8AACooCICRGIumQEpGtupkQwBgNSGYphBFqYF4KgQ4CBBQAdKBhjWIkGAOSU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:8873778988737723
Difference Hash:100c30b2b2b20c30
Wavelet Hash:00003c19d9d8c0d8
Color Hash:#3a7853

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data