Security Scan Report: pub-f6267a1907b44a078354e073bd286e20.r2.dev

Redirected to:
https://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.html
Site favicon
Submitted: Jul 12, 2026, 4:51:46 AMCompleted: Jul 12, 2026, 4:53:20 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 7 domains to perform 3 HTTP transactions. The main domain is pub-f6267a1907b44a078354e073bd286e20.r2.dev and was registered NaN years ago.

Submitted URL: http://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.html

Effective URL: https://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.htmlRedirected

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

The site impersonates The Courier Guy and solicits payment, indicating a high‑risk phishing scam.

Risk Factors
Brand impersonation of a well‑known courier service
Payment request on a non‑official domain
Unranked domain with no reputation
Domain age information unavailable

Details

Page Title

The Courier Guy

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(56%)

Domain Information

The domain name 'pub-f6267a1907b44a078354e073bd286e20.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-f6267a1907b44a078354e073bd286e20'. The registrable portion 'r2' spans 2 characters holding zero vowels versus one consonant, notching one digit. Breaking it apart gives two words: r, 2. Median word length is 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.html

Page Load Overview

4.57s
Total Load Time
68
HTTP Requests
28
Domains
2.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:643 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking56% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
56%
government public service
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1418.66.102.11Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
965.9.175.114Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
9192.178.183.95Google · CDNUnited States
AS15169Google LLC
9157.240.0.6Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
9104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
923.3.88.65Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
9142.251.13.97Google · CDNUnited States
AS15169Google LLC
687--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11204E69362A029FA1B338137538E99C8B14C4CD5B913E9E6F5DE98490BC96FD0D13B27

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:PBP0FVuUmSmemSm8mSmRmSmNXmSm4mSmkmSmewspOO7BWuS5E/TdJlf5fef9fgf3:Cbh7BW6Y0wB1swCP7zW0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:177442:IEZAIApAFhU4EBImMEIgwCHICuA3hDLJAtBw2AQGAggFsKnQHgZABTMkOrQ9CCthGJ0BQgL0kdGMhEAUgDRqcGhkxGCEzAQT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:07bbb9c989f3e7ff
Perceptual Hash:bc09863419e7cf3c
Difference Hash:da77639b33274c12
Wavelet Hash:02b381c888f9e3ff
Color Hash:#65783a

Other Hashes

Crop Resistant:da77639b33274c12

Scan History

Scan history not available

Unable to load historical scan data