Security Scan Report: onboardingsdocumentstosign-dpf0631l6cj3.edgeone.dev

Submitted: Sep 27, 2026, 11:37:20 PMCompleted: Sep 27, 2026, 11:37:54 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Disposable edgeone.dev subdomain impersonating Millennium Hotels' onboarding, harvesting names, NRIC/FIN/passport numbers under a fake brand — do not submit personal data.

Risk Factors (4)
Brand impersonation of a different entity (Millennium Hotels and Resorts) on a non-official domain
Collection of government identity numbers (NRIC / FIN / Passport) under a false brand identity
Hosted on a free/instant subdomain namespace where the actual page creation date is unknown and untrusted
Domain not present in Cisco Umbrella top-1M while claiming to represent a major hotel brand
Domain age information unavailable

Details

Page Title

New Joiner Document Signing — Millennium Hotels and Resorts

Scan Type

public

Domain Name Analysis

The domain 'onboardingsdocumentstosign-dpf0631l6cj3.edgeone.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'onboardingsdocumentstosign-dpf0631l6cj3'. The core label 'edgeone' covers 7 characters containing four vowels alongside three consonants. Tokenizing the label suggests 2 words: edge, one. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://onboardingsdocumentstosign-dpf0631l6cj3.edgeone.dev/

Page Load Overview

0.97s
Total Load Time
1.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:965 chars
Detector Agreement:50%

Website Classification

Primary Category

corporate business56% confidence
Type: static
Method: ml+structural

All Detected Categories

corporate business
56%
government public service
49%
documentation technical
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
243.174.247.29Singapore
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
43--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14365023BED110C157374C20BDB1FD987EDBA5F1B6D82C9D67A1E428A0BA5B73806C069

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24576:w0RTK6J4Uk+VqAPndHtZgzece2Vd45B313ZOg+HyC6KJ4MAp8DQAC2sjmOYJXfmt:rTKaHJa1SuJ2NhdYnAuiBP

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1519527:EEGJQBykQgAhiVqFK74QRSSSi6mQwKxuFFguCEAoMRRkKfVKFAYTRAwBJBM0AgECxEpugxzGgaACUgUYCIVAShKVCFX1BY5I

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:080c3e7e9e042000
Perceptual Hash:9ed361389ec33c1c
Difference Hash:5a386c6c38384000
Wavelet Hash:0a7e7f7f1e7e0000
Color Hash:#79a0d2

Other Hashes

Crop Resistant:5a386c6c38384000

Scan History

Scan history not available

Unable to load historical scan data