Security Scan Report: still-bonus-f2eb.2415054122105.workers.dev

Site favicon
Submitted: Aug 9, 2026, 12:50:02 PMCompleted: Aug 9, 2026, 12:51:21 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 2 HTTP transactions. The main domain is still-bonus-f2eb.2415054122105.workers.dev and was registered NaN years ago.

Submitted URL: https://still-bonus-f2eb.2415054122105.workers.dev/

AI Security Verdict

Confirmed Scam

Confidence: 94%

10
Risk Score

The site impersonates the French tax authority and harvests banking details on a workers.dev subdomain, confirming a high‑risk brand‑impersonation scam.

Risk Factors
Brand impersonation on mismatched domain
Payment collection fields on untrusted hosting subdomain
Unknown subdomain creation date
Domain age information unavailable

Details

Page Title

Remboursement – DGFiP

Scan Type

public

Language

🇫🇷

French

(80% confidence)

Category

e-commerce

(40%)

Domain Information

Domain 'still-bonus-f2eb.2415054122105.workers.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'still-bonus-f2eb.2415054122105'. The second-level label 'workers' is 7 characters long containing two vowels alongside five consonants. Tokenizing the label suggests one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://still-bonus-f2eb.2415054122105.workers.dev/

Page Load Overview

0.96s
Total Load Time
13
HTTP Requests
5
Domains
471 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:fr
Text Length:1,715 chars
Detector Agreement:67%

Website Classification

Primary Category

e-commerce40% confidence
Type: static
Method: structural

All Detected Categories

e-commerce
40%

Detected Features

Payment

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.21.37.122Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4142.251.14.95Google · CDNUnited States
AS15169Google LLC
133--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T157B27B5028F1ECB340DB48D919764A2A6DF84347D65A0148FBAD87FA2FFACADD233415

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:n0A+ZsBYoYXw83G2BvewVeb1DojqXP2Bm5R82BmP:n0As/FLBv5Vy1DojqXe21c

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24910:JYAtcYuIphpIKYKgYEQgj0NQakCKGgLQ1AQgECBCwRKBic+RTr2JFMYFBxECAlJSAwHgGIEgFIEEW+I2EQ01kFKDA4KYBNon

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7ffeffffff00ffff
Perceptual Hash:84c4df1b91a72ba9
Difference Hash:c420a68ec8510000
Wavelet Hash:3e0013634e00ffff
Color Hash:#842d86

Scan History

Scan history not available

Unable to load historical scan data