Security Scan Report: urlshort-linkmu9uwm4tctbb.banksystem.workers.dev

Submitted: Sep 21, 2026, 6:50:07 AMCompleted: Sep 21, 2026, 6:50:26 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page impersonating N26 on a workers.dev domain; uses urgency and a fake data-verification form to harvest names, addresses, phone numbers and IBANs. Do not enter any data.

Risk Factors (5)
Brand impersonation of N26 on a non-official domain
Harvests IBAN, phone numbers and full identity/address data
Urgency and account-restriction threats to force data submission
Deceptive subdomain namespace ('banksystem') mismatched with claimed brand
Hosting platform subdomain with unknown creation date
Domain age information unavailable

Details

Page Title

Dringende Datenverifizierung | N26

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'urlshort-linkmu9uwm4tctbb.banksystem.workers.dev' is registered, featuring subdomain 'urlshort-linkmu9uwm4tctbb.banksystem'. The second-level label 'workers' is 7 characters long holding 2 vowels versus five consonants. Word splitting yields 1 word: workers. Average segment length settles at seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://urlshort-linkmu9uwm4tctbb.banksystem.workers.dev/site/n26-uglwrh

Page Load Overview

0.67s
Total Load Time
154 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:3,790 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking86% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
86%
government public service
73%
documentation technical
73%
adult content
73%
cryptocurrency blockchain
47%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.21.65.106Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.67.145.35Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
62--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15213D6626EF5602AB413C486BB85772FF6259013DD0A4384F69C4A688FC7FD26D2F748

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:sIJetN3y3gOrAht4lpJLIqBvOBv328hanMG7Cy6x:sIJf+l28hRiz6x

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:45380:yVAEV5mWjVqCIHxQFAzIWBJWE8ICAAgB8Ao5SAX6AIABKhiMASFUhjaKAYIwnDADSBBmBmBMhIPlGAyiOQmnGEHwtAgYkLEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fe968e8f8f9ffff1
Perceptual Hash:bc1664936993699b
Difference Hash:44243c3c3c3ec827
Wavelet Hash:009682878f87fff1
Color Hash:#1f6793

Other Hashes

Crop Resistant:44243c3c3c3ec827

Scan History

Scan history not available

Unable to load historical scan data