Security Scan Report: pub-b66dec0cc4eb4cfb824497aaa022db80.r2.dev

Submitted: Sep 28, 2026, 3:52:25 PMCompleted: Sep 28, 2026, 3:52:58 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Contentless R2-bucket page with no forms or malware, but its scripts contact an unranked .moscow domain — obfuscated purpose, not enough for a scam verdict. Avoid entering data or downloading anything.

Risk Factors (3)
Opaque, contentless page hosted on a free/instant cloud-storage bucket subdomain where the apex age is not attributable to the page
Cross-origin script request to an unranked third-party domain (newmmsdanishkronenew.moscow) unrelated to the hosting platform, with a naming pattern consistent with unofficial finance/fraud lures
No legitimate page identity: no title, no text content, no disclosure of purpose
Safety Factors (5)
No credential-harvesting or payment form present (0 forms, 0 password fields, 0 disguised password fields, 0 payment fields)
No JavaScript YARA malware, no known phishing kit in the kit roster, no high-precision native-YARA hits
No Google Safe Browsing or IDS phishing/malware/C2 alert — the 4 Suricata alerts are all MEDIUM ET INFO observations of a Cloudflare R2 domain in DNS/TLS, which is informational
No brand impersonation detected and no cross-origin credential exfiltration detected
One third-party script host is in the top-1M popularity list (cdnjs.cloudflare.com)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'pub-b66dec0cc4eb4cfb824497aaa022db80.r2.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'pub-b66dec0cc4eb4cfb824497aaa022db80'. Its registrable label 'r2' stretches across 2 characters with 0 vowels and 1 consonant; bonus characters include 1 digit. Splitting it apart reveals two words: r, 2. Expect one character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-b66dec0cc4eb4cfb824497aaa022db80.r2.dev/index.html

Page Load Overview

0.58s
Total Load Time
47 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

0
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
43--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T129C1B9703979101D6247D26162F5DBAE4D3FD60697038C3AB3A811D78BCD88C8ABB6D6

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:L+ky8Gvji6gMlf9Fnrgx0qd2nGDTuOM3ht:LtZsjXT91gZ4GDyOet

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5725:6IgAYcGrCBMJLQAWiAYIpIAiAggsh9CggoJkACIAAAFgiCDICyRAAkIAO0CkIwAAAEWqgQAAgMkZAcKC1hEmEBggKBAtU0AB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6269999663399cc
Difference Hash:0008000c0c000800
Wavelet Hash:0f0f0f07243c3030
Color Hash:#8f1f93

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data