Security Scan Report: qerwrrsfwetrans.edgeone.dev

Site favicon
Submitted: Aug 8, 2026, 1:45:20 PMCompleted: Aug 8, 2026, 1:47:47 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 2 countries across 2 domains to perform 2 HTTP transactions. The main domain is qerwrrsfwetrans.edgeone.dev and was registered NaN years ago.

Submitted URL: https://qerwrrsfwetrans.edgeone.dev/?email=a.b@c

AI Security Verdict

Low Risk

Confidence: 84%

3
Risk Score

The page impersonates WeTransfer, is hosted on an unknown‑age subdomain, and resolves to a known malicious IP, indicating a high‑risk phishing attempt.

Risk Factors
Brand impersonation without matching domain
Known‑malicious IP associated with the site
Unknown subdomain age on a hosting platform
External network request to unrelated domain
Safety Factors
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 7 to 3
Domain age information unavailable

Details

Page Title

WeTransfer

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

download file sharing

(54%)

Domain Information

You're looking at domain 'qerwrrsfwetrans.edgeone.dev' on the developer-focused generic top-level domain (.dev); it also runs on subdomain 'qerwrrsfwetrans'. The second-level label 'edgeone' is 7 characters long split between four vowels and 3 consonants. It segments into 2 words: edge, one. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://qerwrrsfwetrans.edgeone.dev/?email=a.b@c

Page Load Overview

17.05s
Total Load Time
20
HTTP Requests
4
Domains
467 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:473 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing54% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

download file sharing
54%
technology software
43%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1043.174.247.29Singapore
10143.95.212.125United States
AS31898Oracle Corporation
202--

Page Statistics

20
Requests
4
Unique Domains
468.8 KB
Total Size

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EED208679CA610165217B0B89FAF6B08309AD10B860BCD103EFC87E85FC3D65D5D76AE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:Vp58mW6+yWH9ukQqqnIkQqqn5dCGCzUKKnf1HbOuaJWWc:VRfFPgSVzXKnf1HbtgU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28599:kZYAUyAggMUAILHASCIn5aNNASMIDsKaCWZjaETVAQhMBC5IHAQhADIoGxzDQpCG2RqAWhKIeGIlBaRAYAELAcBqkpNARooF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:01c0c0c0c0c00000
Perceptual Hash:f8e80f0ba80bf8f8
Difference Hash:432021a8a0804000
Wavelet Hash:c1c0f0f0f0e0f0f0
Color Hash:#d22d59

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data