Security Scan Report: workers-playground-muddy-wave-3b13.cadeviw540.workers.dev

Site favicon
Submitted: Jul 16, 2026, 12:45:56 AMCompleted: Jul 16, 2026, 12:49:37 AMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 1 country across 7 domains to perform 2 HTTP transactions. The main domain is workers-playground-muddy-wave-3b13.cadeviw540.workers.dev and was registered NaN years ago.

Submitted URL: https://workers-playground-muddy-wave-3b13.cadeviw540.workers.dev/2606:4700:3031::ac43:dd2b/

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Page impersonates WeTransfer, harvests login credentials, and triggers Safe Browsing and IDS alerts – treat as high‑risk phishing.

Risk Factors
Brand impersonation of WeTransfer
Credential harvesting form on unknown-age subdomain
External form submission endpoint
Safe Browsing social engineering threat
High‑severity IDS hex‑obfuscation alerts
Domain age information unavailable

Details

Page Title

WeTransfer

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

download file sharing

(67%)

Domain Information

The domain 'workers-playground-muddy-wave-3b13.cadeviw540.workers.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'workers-playground-muddy-wave-3b13.cadeviw540'. The second-level label 'workers' is 7 characters long containing two vowels alongside five consonants. Breaking it apart gives 1 word: workers. Median word length is 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://workers-playground-muddy-wave-3b13.cadeviw540.workers.dev/2606:4700:3031::ac43:dd2b/

Page Load Overview

6.91s
Total Load Time
35
HTTP Requests
8
Domains
221 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:802 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing67% confidence
Type: webapp
Method: ml+structural

All Detected Categories

download file sharing
67%
adult content
51%
documentation technical
33%
corporate business
27%
corporate
25%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
5104.21.35.122Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
53.174.46.90Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
5104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5142.251.110.95Google · CDNUnited States
AS15169Google LLC
5104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
356--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117437DB71500FC996B034EDDE2D07B149CAEE65FE70A40887EE905E5E2E2E81DC25939

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:XnyblieaJq5f44erUPhmegbepeaJq5f44erUPhmegbeE1arAyUAX:Xnybl3UUJ5gy6UUJ5gyE+zUAX

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57272:KQDpAaBgRQpYRcGALQEwAajHUUywDQOQs4VDFAGmDGgGwIIOiBCAAAiEUXwIkMCBhR9Aik5kNtMLcgNAxQ4QtAoAIlsAYEIC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1f0f87c7cf07270f
Perceptual Hash:b338cdcccc3338cc
Difference Hash:febc9d88ac88cafc
Wavelet Hash:1f0f0707cf070f0f
Color Hash:#c5878e

Scan History

Scan history not available

Unable to load historical scan data