Security Scan Report: pub-c39e7206571b493dbc14bab160b077f4.r2.dev

Submitted: Sep 30, 2026, 4:55:05 AMCompleted: Sep 30, 2026, 4:55:57 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 87%

8
Risk Score

Page is a known attack-kit Turnstile 'Verifying site connection...' gate hosted on an anonymous R2 bucket, using a hidden base64 next-stage URL and a third-party sc.php loader — high-confidence phishing kit.

Risk Factors (4)
Known malicious phishing kit (Turnstile gate / sc.php loader) confirmed by analyst-vetted roster and native YARA scanner
Content hosted on an anonymous, unranked Cloudflare R2 public bucket where any party can publish instantly — platform apex age not attributable to this page
Content is deliberately opaque: only a fake 'connection verification' gate is shown to users before a hidden redirect stage (base64-encoded next-stage URL)
Cross-origin script from a third-party (likely compromised) site loading admin/js/sc.php, consistent with kit loader infrastructure
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

You're looking at domain 'pub-c39e7206571b493dbc14bab160b077f4.r2.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-c39e7206571b493dbc14bab160b077f4'. Its registrable label 'r2' stretches across 2 characters containing zero vowels alongside 1 consonant; it also includes one digit. Splitting it apart reveals two words: r, 2. Average segment length settles at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-c39e7206571b493dbc14bab160b077f4.r2.dev/index.html

Page Load Overview

0.99s
Total Load Time
55 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:74%
Script:Latin
Direction:ltr

Detection Details

Text Length:28 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0172.67.168.81Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.21.94.138Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
56--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1600144C3A616CD140D4784F01760910C002ACA5CD7C69C8A2AD6421FE9CA7DD8E516C8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:kx2REXy7iLHskwGWGJPvKNGexV/mgKpOo7DzBkCuoerpee75UDCd8eG:kcACMWoXKVV/qhFuJke7YSG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:694:AAAAAAAAAAAAAAAAAIAAAAAAAAACBgAAAAAAABAAAAAAAAAAAAIAgAICCAABAgAAAAABAAAgAAAAAAAAAAAAIAAAAAAAAQAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:b323cccc3333cccc
Difference Hash:0000000808000000
Wavelet Hash:f0f0d8c0e4fcf0f0
Color Hash:#d22d5c

Other Hashes

Crop Resistant:0000000808000000

Scan History

Scan history not available

Unable to load historical scan data