Security Scan Report: dndair.com

Site favicon
Submitted: Sep 30, 2026, 12:50:18 PMCompleted: Sep 30, 2026, 12:50:57 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Adobe Document Cloud phishing kit on dndair.com: fake shared-document page harvests email, password and OTP, redirecting sign-ins to unrelated domains; flagged by Google Safe Browsing for Social Engineering.

Risk Factors (5)
Brand impersonation of Adobe Document Cloud on an unrelated domain
Credential-harvesting login form (email + password) plus 6-digit OTP capture
Google Safe Browsing Social Engineering detections (2 instances)
Credential exfiltration to third-party domains (jerimavon.com, clarkservic.icu) with base64-encoded email in the URL
Unranked domain presenting itself as a major brand
Domain age information unavailable

Details

Page Title

Cloud Share

Scan Type

public

Domain Name Analysis

The domain name 'dndair.com' uses the commercial generic top-level domain (.com) without a subdomain. Count 6 characters in 'dndair' with 2 vowels and 4 consonants. Splitting it apart reveals two words: dnd, air. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dndair.com/iv/cook/index.php

Page Load Overview

1.85s
Total Load Time
612 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:570 chars
Detector Agreement:100%

Website Classification

Primary Category

real estate property86% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

real estate property
86%
technology software
77%
documentation technical
67%
cryptocurrency blockchain
55%
download file sharing
53%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
850.87.143.172Phoenix, Arizona, United States
AS46606Unified Layer
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1192.178.170.95Google · CDNUnited States
AS15169Google LLC
1172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.71.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.250.154.95Google · CDNUnited States
AS15169Google LLC
2316--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DD72F921BAAD0827107B90E473B6DF4935749513FE13CD0476FCA7E95FD4E6AA822388

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:umtpYEeRKtf90dKDNzI5yZsD39u9ZMChxhaHx:umLYEhEANzI5yZsD3sP14x

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17259:EJCADHEohpEogyaKhI1Hg0AgAwABQi0QwKSDAAiSVN1wjGZCQWBATRAIg4UhSAAAySjUMKBT8AJgCRjoeCgiUSZJEQ2TrgYC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7c7e7e7dfff
Perceptual Hash:b663c963cd9c4389
Difference Hash:cc4d0c0c4c0c342c
Wavelet Hash:e6e7878687878386
Color Hash:#2d2fd2

Scan History

Scan history not available

Unable to load historical scan data