Security Scan Report: 1f43a3e4.57b79ffb3043f32930fb5bee.workers.dev

Site favicon
Submitted: Aug 13, 2026, 12:50:26 AMCompleted: Aug 13, 2026, 12:52:57 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Known Cloudflare-brand-impersonating Turnstile phishing gate kit hosted on a workers.dev subdomain, targeting a specific victim email. Do not interact.

Risk Factors (5)
Known malicious phishing kit (Turnstile gate / cfForm) matched by high-precision YARA rule
Impersonation of Cloudflare's security-challenge brand on a third-party domain
Randomized 32-hex-character subdomain on the free workers.dev platform with unknown creation date
Victim-specific email address embedded in the URL query string
Heavy use of eval() for dynamic code execution
Domain age information unavailable

Details

Page Title

Just a moment...secondary capture

Scan Type

public

Domain Name Analysis

The domain '1f43a3e4.57b79ffb3043f32930fb5bee.workers.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain '1f43a3e4.57b79ffb3043f32930fb5bee'. The registrable portion 'workers' spans 7 characters containing two vowels alongside five consonants. It segments into 1 word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://1f43a3e4.57b79ffb3043f32930fb5bee.workers.dev/?email=david.pereira@secpro.co

Page Load Overview

0.96s
Total Load Time
562 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:200 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical67% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
67%
government public service
63%
blog personal website
53%
news media journalism
49%
adult content
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4188.114.96.3Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
82--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A061963F6A21701AD6F38A7631F163DE3920E108D703879AEDB7A7444ED266B1E1174D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:PzTW4lNvkiWUZKAbWYBUO36yKrnVjbv8+qfOcqwFtiGNirSVmu/sC7e4k5:PGeiURtBUOXanFISch+rSOcg5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3318:ABg5AkABSIIczAFAIIQAIEACAAgAAQ4mgACEAAgACgAYAFIAAkgIhFAgAACABABKABAAAAAEAiMwUgSAAkAEGZEDAAApB0CA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc783c3ffffffe7
Perceptual Hash:b038c3cfc7cc6631
Difference Hash:00181e3600000008
Wavelet Hash:ffc7c3df30303c00
Color Hash:#2d8652

Other Hashes

Crop Resistant:00181e3600000008

Scan History

Scan history not available

Unable to load historical scan data