Security Scan Report: excel-document-secure.pages.dev

Redirected to: https://excel-document-secure.pages.dev/

Submitted: Jan 14, 2026, 7:10:15 PMCompleted: Jan 14, 2026, 7:11:37 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 1 HTTP transaction. The main domain is excel-document-secure.pages.dev and was registered NaN years ago.

Submitted URL: http://excel-document-secure.pages.dev/

Effective URL: https://excel-document-secure.pages.dev/Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing site impersonating Microsoft Excel login; do not enter credentials.

Risk Factors
Credential harvesting form on a non‑official domain
Impersonation of Microsoft brand on an unranked domain
Domain age information unavailable

Details

Page Title

PO

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(42%)

Domain Information

The domain name 'excel-document-secure.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'excel-document-secure'. The second-level label 'pages' is 5 characters long containing two vowels alongside three consonants. Breaking it apart gives one word: pages. Average segment length settles at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://excel-document-secure.pages.dev/

Page Load Overview

0.61s
Total Load Time
6
HTTP Requests
2
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:329 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical42% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
42%
technology software
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3188.114.96.3United States
AS13335CLOUDFLARENET
3104.26.8.44United States
AS13335CLOUDFLARENET
62--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1ABE44C72B68A242DB137C559F5A0AADC3E28C033E2230EBDFE95F576C6D14891133B65

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:R7RlLDzgz3Qr/hKM4DtFG37MbphKYV3mXzaoDBCWVU4wLdPFX0:RX/gzArEBuIbSYIXU0US

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:686542:cQlgOLLIUiAAJAbBCSigQWaHYAhoWEAMIMAYEJRBrW0AWgyIDUD1huAEhZExBqghdyKQAadqHeMTgHRkkYFAAEqGgkAQYIPo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:997362589d764873
Difference Hash:b0ccb232b2b28ca0
Wavelet Hash:00007a1e3e7f7f1e
Color Hash:#bf4090

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data