Security Scan Report: pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev

Redirected to:
https://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm
Submitted: Sep 10, 2026, 4:50:14 AMCompleted: Sep 10, 2026, 4:51:41 AMpubliccompleted

This website contacted 16 IPs in 1 country across 11 domains to perform 22 HTTP transactions. The main domain is pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev and was registered 18 years ago.

Submitted URL: http://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm

Effective URL:

https://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

The page hosts credential‑collecting forms, is unranked, flagged by Safe Browsing for phishing, and triggers a critical IDS alert, indicating a high‑risk phishing site.

Risk Factors
Unranked domain with no reputation
Credential collection forms on a cloud‑storage hosted site
Safe Browsing phishing classification
Critical IDS alert indicating possible shellcode
Domain age information unavailable

Details

Page Title

Credentials

Scan Type

public

Domain Name Analysis

The domain 'pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'pub-d44e201c1f3e400586cb81b0f2d48f61'. Count 2 characters in 'r2' holding zero vowels versus 1 consonant, plus 1 digit. Tokenizing the label suggests 2 words: r, 2. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm

Page Load Overview

9.53s
Total Load Time
472 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:691 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical81% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
81%
technology software
80%
news media journalism
80%
documentation technical
79%
government public service
78%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.20.95Google · CDNUnited States
AS15169Google LLC
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1192.178.183.138Google · CDNUnited States
AS15169Google LLC
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1172.217.117.4Google · CDNUnited States
AS15169Google LLC
1192.178.183.113Google · CDNUnited States
AS15169Google LLC
1142.251.127.94Google · CDNUnited States
AS15169Google LLC
2216--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19CE3067D7611CC4EAD3399BFFCA82FD090149E5BECCDABC40459845A6FE14AA35082DB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:KgZFgVWFEGtig7o2bhf7g7NLl3M4KLuwdmUkCikYkORodfKQxSYd8js9/1m4IDgU:JPOLijROgMGPgzv6gVbqcijl0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:156321:RU2B0BAFQqSghA+IRiIKAhCIClFBNhFCDOCbCAAQRAEmMw3BZAgEZGSKAATXOYgDUFJB4cNw45jaDqApSoRAyYoWVIlkgAsg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd8d8d0d0d0
Wavelet Hash:3f273f3f3f300000
Color Hash:#86532d

Scan History

Scan history not available

Unable to load historical scan data