Security Scan Report: www.gov-pk.workers.dev

Redirected to:
https://gov-pk.cloudflareaccess.com/cdn-cgi/access/login/www.gov-pk.wo...
Submitted: Sep 16, 2026, 5:47:54 PMCompleted: Sep 16, 2026, 5:48:37 PMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is gov-pk.cloudflareaccess.com and was registered 7 years ago.

Submitted URL: https://www.gov-pk.workers.dev

Effective URL:

https://gov-pk.cloudflareaccess.com/cdn-cgi/access/login/www.gov-pk.wo...
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Disposable .workers.dev subdomain impersonating a national government's webmail and tied to APT SideWinder malware on two independent threat feeds — a clear phishing/lure page; do not enter credentials.

Risk Factors (4)
Government/brand impersonation (gov-pk, webmail-pnra) on a throwaway hosting subdomain
Malware Indicators of Compromise on the primary domain, corroborated by two independent feeds (APT SideWinder)
No legitimate business entity, no ranking, no age attributable to the page itself
Login-code / email credential collection under a spoofed government identity
Domain age information unavailable

Details

Page Title

Sign in ・ Cloudflare Access

Scan Type

public

Domain Name Analysis

Domain 'www.gov-pk.workers.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'www.gov-pk'. The core label 'workers' covers 7 characters with two vowels and five consonants. It segments into one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.gov-pk.workers.dev

Page Load Overview

1.01s
Total Load Time
12 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:64%
Script:Latin
Direction:ltr

Detection Details

Text Length:117 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software64% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
64%
government
48%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.19.195.29Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0172.67.133.154Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.21.5.158Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
23--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16DE239D7B160B62A1463E97C971FBB0C7328D4B6580217D8B99C8964CFC7F9285A7D0C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Gs08JpCrAzwzr32FNX7LZ1zH6gMrIvyv/lxbDDyUljWt5P66M63V3:A+e32FNrFdanHbhljGxF

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:32781:CTUKOIEKbAC4h1pMgGUgp0xyHKQaYEQIMBIEokHAAuF9QUwAoDgHBvkjQISIqSigQIPAQQEowjJoNBACFNgA8A+1mgDKUEyL

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7efe7e7ffff
Perceptual Hash:b399cc6633992666
Difference Hash:00084c584d0c3008
Wavelet Hash:f0f0c0c0e0f8f0f0
Color Hash:#2dd298

Other Hashes

Crop Resistant:00084c584d0c3008

Scan History

Scan history not available

Unable to load historical scan data