Security Scan Report: phb2-9if.pages.dev

Site favicon
Submitted: Jan 2, 2026, 8:08:41 PMCompleted: Jan 2, 2026, 8:10:04 PMpubliccompleted
Loading additional data...

Summary

This website contacted 21 IPs in 4 countries across 15 domains to perform 56 HTTP transactions. The main domain is phb2-9if.pages.dev and was registered NaN years ago.

Submitted URL: https://phb2-9if.pages.dev/nl

AI Security Verdict

High Risk

Confidence: 95%

8
Risk Score

High‑risk phishing site impersonating Ookla Speedtest; do not use.

Risk Factors
Malicious Indicators of Compromise on primary domain
Brand impersonation of a reputable service (Ookla Speedtest)
Unranked domain presenting a major brand
Error page that could be used as a social‑engineering lure
Domain age information unavailable

Details

Page Title

Speedtest door Ookla - De wereldwijde breedbandsnelheidstest

Scan Type

public

Language

🇳🇱

Dutch

(80% confidence)

Category

technology software

(43%)

Domain Information

Within the developer-focused generic top-level domain (.dev), 'phb2-9if.pages.dev' is registered; it also runs on subdomain 'phb2-9if'. The second-level label 'pages' is 5 characters long split between 2 vowels and 3 consonants. Tokenizing the label suggests 1 word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://phb2-9if.pages.dev/nl

Page Load Overview

2.76s
Total Load Time
51
HTTP Requests
16
Domains
2.7 MB
Total Size

Language Analysis

Primary Language

🇳🇱Dutch
Code: nl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:nl
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:nl
Text Length:2,407 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software43% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
43%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11162.19.138.119Germany
252.202.155.16United States
2142.250.185.202Sweden
252.72.119.204France
252.200.159.203Unknown
218.245.31.9Unknown
2142.250.184.194Unknown
2188.114.96.3United States
AS13335CLOUDFLARENET
2146.75.122.219Unknown
223.56.202.65Unknown
5121--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BFF308F522BC535D908B875DEF36B608630FE0B7B5A689D5BB5D8F644B839E4E803840

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:EsM+E+6H4yvZs0xE6J/CgbcVKzoKeMXKLnpI6dDcPXE+ymj6aslNzlbsjq0Aok3R:U7bZbagbcVMaWUZD+3UbwnZL+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:168430:ATomSiRVzkJ9cQOACAmVVJQDUAcE1AoaRzkIgAEBJlKIiMGbYCBBs1EEECAjOASCYGBlDoI6oRJ0bRRIKtyFecaHkBEWq5EM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffff0100
Perceptual Hash:aad52af133c58a55
Difference Hash:9971616111010101
Wavelet Hash:7f3b3b3b073f0100
Color Hash:#e0a46c

Other Hashes

Crop Resistant:9971616111010101

Scan History

Scan history not available

Unable to load historical scan data