Security Scan Report: pub-d197a83cf813475088723e020c96b503.r2.dev

Submitted: Sep 29, 2026, 2:53:47 AMCompleted: Sep 29, 2026, 2:54:22 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

Generic Korean webmail login page hosted on a Cloudflare R2 public bucket, collecting email/password without any legitimate brand identity. Likely credential phishing; do not enter credentials.

Risk Factors (3)
Credential login form (email + password) hosted on cloud storage
Generic webmail login page with no verifiable brand or site owner
Unranked domain with unknown page age on a free/public bucket namespace
Domain age information unavailable

Details

Page Title

웹메일 - 로그인

Scan Type

public

Domain Name Analysis

You're looking at domain 'pub-d197a83cf813475088723e020c96b503.r2.dev' on the developer-focused generic top-level domain (.dev); it also runs on subdomain 'pub-d197a83cf813475088723e020c96b503'. Count 2 characters in 'r2' containing 0 vowels alongside 1 consonant, notching one digit. Word splitting yields two words: r, 2. The median word length lands at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-d197a83cf813475088723e020c96b503.r2.dev/san.html

Page Load Overview

0.93s
Total Load Time
56 KB
Total Size

Language Analysis

Primary Language

🇰🇷Korean
Code: ko
Confidence:60%
Script:Hangul
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:42 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ko

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0172.217.116.4Google · CDNUnited States
AS15169Google LLC
0208.91.114.103Langley, British Columbia, Canada
AS40934Fortinet Inc.
0156.226.121.244Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
0104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
69--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13192D6115DF108021343886ABF576946F552C807AA4FCD0CB6ACAF94EF81E63D8637BD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:rvFYLaAyIF7/7lxYtO2NFjGJzrd+rI0mjx8+TL14IHYzUChzc7:rvFcVyIFjkBfjIrsIehlc7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:20290:JSbAOFg2IKQAIRhIAAAZAzQCQ9SokgCETOX0oMLJASGMBKEREBAQ8FocERMkYySEC0QgVESX1gkMgHEQREBMoQIYkAEAMjBI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c1c1810000000
Perceptual Hash:dd99666623393166
Difference Hash:0a22125226020202
Wavelet Hash:f0f8f8f80e0e0e0e
Color Hash:#2d8649

Other Hashes

Crop Resistant:0a22125226020202

Scan History

Scan history not available

Unable to load historical scan data