Security Scan Report: email-nsd-gov-pk-2fa.pages.dev

Site favicon
Submitted: Sep 18, 2026, 12:45:32 AMCompleted: Sep 18, 2026, 12:47:30 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Fake Zimbra 'Sign In' page on a free pages.dev subdomain mimicking a government email/2FA portal, impersonating both Zimbra and a third-party Cyber-Team Document Scan. Avoid entering any credentials.

Risk Factors (5)
Impersonation of Zimbra and of a third-party 'Cyber Team / Document Scan' entity on a non-official domain
Deceptive hostname embedding a government-style identifier (nsd-gov-pk) plus '2fa'
Unranked domain with no reputation on an instant-publish hosting platform
Login-gate consent prompt used as social engineering rather than a real authentication flow
Inline encoding/decoding JavaScript on a page claiming to be an authentication portal
Domain age information unavailable

Details

Page Title

Zimbra Web Client - Sign In

Scan Type

public

Domain Name Analysis

You're looking at domain 'email-nsd-gov-pk-2fa.pages.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'email-nsd-gov-pk-2fa'. The second-level label 'pages' is 5 characters long split between two vowels and three consonants. Splitting it apart reveals one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://email-nsd-gov-pk-2fa.pages.dev/error.html

Page Load Overview

75.31s
Total Load Time
283 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:193 chars
Detector Agreement:67%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
122172.66.45.29Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
121172.66.46.227Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2432--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B4C150E36A971214F853E2682BE797086235C047E60EC9383FCD6399CF8565999B33CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nBrOCevvyGTC+u8P4BsGWzzR4JTiYWu4gzTYgxtKlqe:BrtevvyGTC+5P4BzWXSJTXe8M

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6075:YTgsQQJBBwQAliRBAYFUoABEoK7IgABBADAAQQBvCiTKICAGUCCAALQkAAQABEwBSBaBgTgAJMJwGMIFgg4AACxTwKACqUIB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data