Security Scan Report: umbrella-8af.pages.dev

Redirected to: https://umbrella-8af.pages.dev/

Submitted: Jan 24, 2026, 3:55:58 AMCompleted: Jan 24, 2026, 3:56:57 AMpubliccompleted
Loading additional data...

Summary

This website contacted 15 IPs in 3 countries across 15 domains to perform 57 HTTP transactions. The main domain is umbrella-8af.pages.dev and was registered NaN years ago.

Submitted URL: http://umbrella-8af.pages.dev/

Effective URL: https://umbrella-8af.pages.dev/Redirected

AI Security Verdict

High Risk

Confidence: 85%

9
Risk Score

Impersonates Speedtest by Ookla on a pages.dev subdomain; high‑risk phishing site.

Risk Factors
Brand impersonation: meta tags claim a major brand (Speedtest by Ookla) on a non‑official domain
Subdomain on hosting platform (.pages.dev) with unknown age
Unranked domain (not in Cisco Umbrella top 1M)
Domain age information unavailable

Details

Page Title

Speedtest by Ookla - The Global Broadband Speed Test

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate

(50%)

Domain Information

Domain 'umbrella-8af.pages.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'umbrella-8af'. The second-level label 'pages' is 5 characters long holding 2 vowels versus 3 consonants. Splitting it apart reveals 1 word: pages. The median word length lands at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://umbrella-8af.pages.dev/

Page Load Overview

1.96s
Total Load Time
79
HTTP Requests
27
Domains
3.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,368 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate50% confidence
Type: spa
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
964.233.167.84United States
AS15169GOOGLE
523.55.163.134Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
5188.114.96.3United States
AS13335CLOUDFLARENET
534.120.133.55Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
5172.217.20.130United States
AS15169GOOGLE
5104.18.87.42United States
AS13335CLOUDFLARENET
5146.75.122.219Frankfurt am Main, Hesse, Germany
AS54113FASTLY
5162.19.138.82Unknown
5184.30.208.159Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
513.226.244.99United States
AS16509AMAZON-02
7915--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10E1408F162B8536D908B879DAF36A618770FE0B7F99649D5B79D8B644B83CE0EC03404

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:xSCE1ws4kl4s0xE6J/CgbcVKzoKeMXKLnpI6dDcPXE+ymj6aslNzlbsjq0Aok3aT:bcX4bagbcVMaWUZD+3UbwnZ4vWM9I

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:195158:SIkaQdQYRkErQeAe0SAo4gICSIMEBgACJAgoACAcQ9FTuGUqacDkBBErAAMGBKBUJSmEg2AyU5geFIKtEYqA1YKADCBBUEAF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:6fbdfdfdfdfd1101
Perceptual Hash:aad523f30af522d1
Difference Hash:9935353131352161
Wavelet Hash:6f1f1b1b3f1f0101
Color Hash:#8240bf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data