Security Scan Report: raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run

Redirected to: blob:https://raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run/e97d1c31-1bce-42b7-a65f-00df40ad5d15#dTAwM2NqZUBzZWt1cmUubmV0

Submitted: Feb 26, 2026, 7:47:34 AMCompleted: Feb 26, 2026, 7:48:58 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 6 domains to perform 8 HTTP transactions. The main domain is .

Submitted URL: https://raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run/#dTAwM2NqZUBzZWt1cmUubmV0

Effective URL: blob:https://raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run/e97d1c31-1bce-42b7-a65f-00df40ad5d15#dTAwM2NqZUBzZWt1cmUubmV0Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Likely credential phishing site; do not enter any login details.

Risk Factors
New or unknown-age domain hosting a credential collection form
Use of blob: URL scheme to hide page source
Unranked, low‑reputation domain (web.val.run subdomain)
Credential harvesting on a site with no established reputation
Absence of legitimate content or organizational context
Domain age information unavailable

Details

Page Title

Mail

Scan Type

public

Language

🇺🇸

English

(70% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run' on the .run top-level domain and includes subdomain 'raja2--ce4928e4123f11f1b5ce42dde27851f2.web'. Its registrable label 'val' stretches across 3 characters with 1 vowel and two consonants. Tokenizing the label suggests one word: val. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://raja2--ce4928e4123f11f1b5ce42dde27851f2.web.val.run/#dTAwM2NqZUBzZWt1cmUubmV0

Page Load Overview

1.42s
Total Load Time
8
HTTP Requests
6
Domains
353 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:70%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:70%
Script Type:Latin
Text Length:113 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4142.251.38.74United States
AS15169Google LLC
1178.63.16.224Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
1172.67.75.9United States
AS13335Cloudflare, Inc.
1104.18.11.207United States
AS13335Cloudflare, Inc.
1104.18.54.45United States
AS13335Cloudflare, Inc.
85--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BA43B0722D1D16406F0389EBFAAB6F546C5C80835326E9ED720D6784FFC269C16EB325

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:sXTly9g3lqlPvXUQv0FP8s20dVa1Dnop58Lx6B+QP4RPH:6JyolqlPMu0FP8s20jcg5wR/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:59921:gEEC0NgdAFAVEAQAAQRIlWe6zGlsSlGA9FCFwUqBBACaSADZpByRYRgAZhFVAGQWMQAgBGQYRpCCo6ChKwLiKGEwAAIAgGhP

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:99cc663399cccc99
Difference Hash:0000b2b2b2b23008
Wavelet Hash:00003c3c1c1c2020
Color Hash:#4073bf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data