Security Scan Report: mobile-connect.pages.dev

Site favicon
Submitted: Sep 29, 2026, 10:52:27 AMCompleted: Sep 29, 2026, 10:53:03 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 68%

5
Risk Score

Contentless 'Loading' gateway on a free pages.dev subdomain that falsely claims Google copyright and calls an unrelated unranked host. No forms or malware found, but the fake Google ownership claim and obfuscated redirect pattern make it unsafe to trust.

Risk Factors (4)
Misappropriated Google copyright/ownership notice on a domain Google does not operate
Obfuscated double-base64 identifier parameter in the URL, a common redirector/malware-funnel technique
Cross-origin fetch to an unranked third-party domain with no visible relationship to the site
Contentless 'Loading' interstitial on an anonymous free hosting namespace
Safety Factors (6)
No forms at all: 0 password fields, 0 payment fields, 0 credential fields
No Indicators of Compromise matched against the page or its resources
No JavaScript malware (YARA) patterns and no known malicious kit in the roster
Network IDS alerts are informational (ET INFO external IP lookup, pages.dev observation) — not phishing or malware signatures
Legal terms/privacy notice text is displayed
No concrete malicious signal (no IoC / YARA / Safe-Browsing / IDS / credential form / brand impersonation) — elevated risk rested on domain age or reputation alone; clamped from 7 to 5
Domain age information unavailable

Details

Page Title

Loading Page

Scan Type

public

Domain Name Analysis

The domain 'mobile-connect.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'mobile-connect'. The core label 'pages' covers 5 characters with two vowels and three consonants. Tokenizing the label suggests 1 word: pages. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mobile-connect.pages.dev/?iduser=TkRnd01BPT0=&Jp=99G51

Page Load Overview

0.41s
Total Load Time
11 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:134 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
news media journalism
40%
government public service
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2172.66.47.99Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.154.119Google · CDNUnited States
AS15169Google LLC
1104.26.12.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1192.178.183.138Google · CDNUnited States
AS15169Google LLC
1192.178.183.101Google · CDNUnited States
AS15169Google LLC
65--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F982C1E93696300B22FCED8FDB3585FB069854B214A7B41EBE4E74E523705E88DB2453

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:1Q5fVLFovLJwpIGl3k7U4ebcT3Kn/QFyaYh5rfMSbOakeGGgVVQ:2F7IGl3kg4ebcTVYj1bOakeGtVVQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17897:8EYQohooMRgkAgBRgF4EJwBh0FYQYRKGiIKQXtMBECEZ6gQElgjgKApBhEK/AYoVh0iuoI6gB8AIqkAVUOoSUAKQohirCE4O

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000083c3c000000
Perceptual Hash:cc3333ccce3331cc
Difference Hash:0000102a20100000
Wavelet Hash:c0c0f4fcf8f0f0f0
Color Hash:#405bbf

Other Hashes

Crop Resistant:0000102a20100000

Scan History

Scan history not available

Unable to load historical scan data