Security Scan Report: quiet-lab-c44b.b29e185437704fe0a494f89f.workers.dev

Site favicon
Submitted: Sep 24, 2026, 12:45:21 AMCompleted: Sep 24, 2026, 12:46:31 AMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 10 HTTP transactions. The main domain is quiet-lab-c44b.b29e185437704fe0a494f89f.workers.dev and was registered 1 month ago.

Submitted URL: https://quiet-lab-c44b.b29e185437704fe0a494f89f.workers.dev/verify?link_id=lnk_ec15884083bc963c

AI Security Verdict

High Risk

Confidence: 97%

7
Risk Score

Confirmed DocuSign/Microsoft device-code phishing on a workers.dev subdomain, exfiltrating user credentials to panel.bcarl24.icu. Do not enter any codes or credentials.

Risk Factors (5)
Brand impersonation of DocuSign and Microsoft on a mismatched free-hosted subdomain
Credential exfiltration to external attacker-controlled .icu panel
Abuse of Microsoft device-login (device code phishing) to capture account access
Free instant-provision hosting (workers.dev) — page creation date unknown
No reputation / unranked domain
Domain age information unavailable

Details

Page Title

DocuSign - Verify Your Identity

Scan Type

public

Domain Name Analysis

Domain 'quiet-lab-c44b.b29e185437704fe0a494f89f.workers.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'quiet-lab-c44b.b29e185437704fe0a494f89f'. The registrable portion 'workers' spans 7 characters containing 2 vowels alongside 5 consonants. Breaking it apart gives one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://quiet-lab-c44b.b29e185437704fe0a494f89f.workers.dev/verify?link_id=lnk_ec15884083bc963c

Page Load Overview

2.09s
Total Load Time
72 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:30%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:1,141 chars
Detector Agreement:75%
Language mismatch: Declared as fr but detected as en

Website Classification

Primary Category

corporate50% confidence
Type: dynamic
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.21.84.162Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3185.215.151.18New York, New York, United States
AS135392MillenialHost Limited
3172.67.195.58Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
103--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18354799A0BCD57B9FA8A0A40AC5F194621FAE1D336054604377F1A9BEF27BCDC871127

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:+m9Xnr8Q+IaOG83nHVIDoNmSDEowJTWxymHCPx6kB0QgO:sWJe0o

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:278852:WEMBGmoUiQIJJArBMEMFADAojbISjC94jKUCkGWVYEEdgFCwCwCREA5IwSCOiJDykSgYwABnsIACAzSEWBBEMsgMhMGHKQDh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c0e4bca5453d3f03
Perceptual Hash:b352cc7131ccce33
Difference Hash:152969494d69691f
Wavelet Hash:c0f8acbc013f3f07
Color Hash:#78763a

Other Hashes

Crop Resistant:152969494d69691f

Scan History

Scan history not available

Unable to load historical scan data