Security Scan Report: bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev

Redirected to:
https://www.google.com/
Submitted: Sep 13, 2026, 1:51:13 PMCompleted: Sep 13, 2026, 1:51:36 PMpubliccompleted

Summary

This website contacted 14 IPs in 1 country across 6 domains to perform 2 HTTP transactions. The main domain is google.com and was registered 18 years ago.

Submitted URL: https://bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev/gCkbDmodqAQL4IjrrQkWWhuAJ2PYdTF_1WZwH20L2aHVMYFn?r421=1785323159.3c0e206030656672.qyQob2vMkawwKx8buSeAomzK9KdAQ5r1qFA5hq7oGgo&_dy=9f1a37ab

Effective URL: https://www.google.com/Redirected

AI Security Verdict

Moderate Risk

Confidence: 78%

5
Risk Score

Randomized workers.dev subdomain flagged as unknown malware by two corroborating threat feeds and used in a cloaked redirect chain to Google; treat as malicious delivery infrastructure — avoid.

Risk Factors
Threat-intel malware match (multi-source corroborated) on the scanned Workers subdomain
Anonymous, free hosting-platform subdomain (workers.dev) with no attributable creation date or reputation
Obfuscated path tokens and parameterized redirect URL typical of cloaked delivery chains
Cross-domain redirect from a flagged host to a high-value destination
Safety Factors
Final destination is the genuine www.google.com consent/search page (Google's own content, not a look-alike)
IDS alerts are ET INFO categorised (Cloudflare Workers domain observation), not phishing/malware/C2 signatures
Domain age information unavailable

Details

Page Title

Google

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

adult content

(61%)

Domain Information

The domain 'bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'bs-deliver-e817.61d8f0e6ac62c139abd08ba5'. Its registrable label 'workers' stretches across 7 characters split between 2 vowels and five consonants. Breaking it apart gives one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev/gCkbDmodqAQL4IjrrQkWWhuAJ2PYdTF_1WZwH20L2aHVMYFn?r421=1785323159.3c0e206030656672.qyQob2vMkawwKx8buSeAomzK9KdAQ5r1qFA5hq7oGgo&_dy=9f1a37ab

Page Load Overview

1.82s
Total Load Time
37
HTTP Requests
6
Domains
918 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:3,652 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content61% confidence
Type: spa
Method: ml+structural

All Detected Categories

adult content
61%
education learning
38%
documentation technical
38%
news media journalism
35%
social media network
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2192.178.183.94Google · CDNUnited States
AS15169Google LLC
2142.251.152.119Google · CDNUnited States
AS15169Google LLC
2142.251.14.94Google · CDNUnited States
AS15169Google LLC
2142.251.151.119Google · CDNUnited States
AS15169Google LLC
2192.178.183.101Google · CDNUnited States
AS15169Google LLC
2142.251.154.119Google · CDNUnited States
AS15169Google LLC
2192.178.183.95Google · CDNUnited States
AS15169Google LLC
2142.251.157.119Google · CDNUnited States
AS15169Google LLC
2142.251.153.119Google · CDNUnited States
AS15169Google LLC
3714--

Page Statistics

37
Requests
6
Unique Domains
924.0 KB
Total Size

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19BE218BBB311783766A3E6F1916F610A3C736067B54C84487598C4F0BCB1D8A8166FFA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:R1oc47mMqbLToXC9czFqXyBjGwl/K7xySoKn+aTsiaTso:XoTqjMlK7jJniL

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33001:kNzBAhAIAAM4QkSFGzjJxAoocsoIBjDUBcIIAJAYDfuhgDGEqBHMDDEASJhJBFgRAIUQbxEUAgG7gyQgMAAGMIGumxZQkgGV

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:183c3c3c3c3c3c18
Perceptual Hash:9bd96464657334d1
Difference Hash:6069697969696969
Wavelet Hash:3c3c3c3c3c3c3c3c
Color Hash:#87a6c5

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data