Security Scan Report: bitter-mode-7090.2415054122105.workers.dev

Redirected to:
https://bitter-mode-7090.2415054122105.workers.dev/succes
Submitted: Aug 9, 2026, 12:50:08 PMCompleted: Aug 9, 2026, 12:51:28 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is bitter-mode-7090.2415054122105.workers.dev and was registered NaN years ago.

Submitted URL: https://bitter-mode-7090.2415054122105.workers.dev/loading.html

Effective URL: https://bitter-mode-7090.2415054122105.workers.dev/succesRedirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

The site impersonates impots.gouv.fr and harvests credentials via forms; treat as high‑risk phishing.

Risk Factors
Brand impersonation of a government service
Credential collection forms on unknown-age subdomain
Cross‑origin submission of passwords to a legitimate domain
Domain age information unavailable

Details

Page Title

Confirmation

Scan Type

public

Language

🇫🇷

French

(80% confidence)

Category

government public service

(56%)

Domain Information

The domain 'bitter-mode-7090.2415054122105.workers.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'bitter-mode-7090.2415054122105'. Count 7 characters in 'workers' holding 2 vowels versus 5 consonants. Tokenizing the label suggests 1 word: workers. The median word length lands at seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bitter-mode-7090.2415054122105.workers.dev/loading.html

Page Load Overview

0.60s
Total Load Time
9
HTTP Requests
2
Domains
199 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:fr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:fr
Text Length:8,519 chars
Detector Agreement:80%

Website Classification

Primary Category

government public service56% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
56%
adult content
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5172.67.208.26Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
92--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T184A37360B5FC1C3A019B8189B3406B0B6E6BC633CA5E505476BE07E42FD7FD06A4B65B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:xZDh07Yj0g93P0sDd+G32SlfqACla2J/24gBBZrMekoTMe9b7TqjqAQ6be:xZ/UVxrgLN8e

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:98821:IevAGBHLaRgZCHE2BgALqCgBUAAJheVFODaEgEsgNoTbBZgGKI5AQADAnAkQRlCsHYJEDDA0wYLWgSE2wgaQOhCiVQwAFlBc

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:002c247e66243c00
Perceptual Hash:b39bcd3218cc6696
Difference Hash:10484cd84c4d6844
Wavelet Hash:007e767e7e647e00
Color Hash:#931f48

Other Hashes

Crop Resistant:10484cd84c4d6844

Scan History

Scan history not available

Unable to load historical scan data