Security Scan Report: pub-348f3aa2a7f245c79c86ae92d678ca3c.r2.dev

Submitted: Sep 15, 2026, 3:45:32 PMCompleted: Sep 15, 2026, 3:46:05 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Fake Deutsche Telekom login page hosted on a public Cloudflare R2 bucket, harvesting passwords via a URL-prefilled email. This is a credential-phishing kit impersonating Telekom — do not enter credentials.

Risk Factors (5)
Impersonation of Deutsche Telekom login on a non-official domain
Password field without an accompanying username field
Credential form on a public cloud-storage bucket (r2.dev)
Prefilled attacker-supplied email address in the URL parameter
Unranked domain not present in Cisco Umbrella top 1M
Domain age information unavailable

Details

Page Title

Telekom Login

Scan Type

public

Domain Name Analysis

Domain 'pub-348f3aa2a7f245c79c86ae92d678ca3c.r2.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-348f3aa2a7f245c79c86ae92d678ca3c'. Count 2 characters in 'r2' with 0 vowels and 1 consonant; it also includes one digit. Breaking it apart gives 2 words: r, 2. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-348f3aa2a7f245c79c86ae92d678ca3c.r2.dev/fs.html?email=lanor@edced1bf7109fb5500433809794d1203c7dc.org

Page Load Overview

3.48s
Total Load Time
175 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:347 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as de

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.2.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
85--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E5D0A7839CE0881405A096A52CE0F05C0C9D695AA781CD507DC960786FC97AA89D3558

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:h4hqIY7YvfAbpli7vkWsr0KPvjVvVuB9d:hRjy7DY02LhVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:1e30f3151d1e71e00802d397fbef77d9

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c0d8981818181800
Perceptual Hash:c8e63299227699dd
Difference Hash:853132333333310d
Wavelet Hash:fcf8f8f8d8d89800
Color Hash:#79c9d2

Scan History

Scan history not available

Unable to load historical scan data