Security Scan Report: pub-37e0821b39ef4ddd869a063490f0f064.r2.dev

Submitted: Sep 29, 2026, 8:53:52 PMCompleted: Sep 29, 2026, 8:54:33 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Fake cPanel Webmail login on a Cloudflare R2 bucket that harvests email credentials and exfiltrates them to kclog.e6f.online; a HIGH-severity phishing IDS alert and a victim email token in the URL confirm a live phishing kit.

Risk Factors (7)
Credential (email + password) capture form on cloud-storage host
Credential exfiltration POST to external domain kclog.e6f.online
Email address embedded in URL fragment as victim tracking token
Network IDS HIGH-severity phishing alert (ET PHISHING CredPost landing)
JavaScript blocks right-click / context menu (anti-analysis)
Impersonates cPanel Webmail login on a non-owner domain
Hosting platform apex age is not attributable to this page (unknown page age; unranked domain)
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Domain Name Analysis

You're looking at domain 'pub-37e0821b39ef4ddd869a063490f0f064.r2.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-37e0821b39ef4ddd869a063490f0f064'. Its registrable label 'r2' stretches across 2 characters split between zero vowels and 1 consonant; bonus characters include one digit. Segmentation suggests two words: r, 2. Expect one character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-37e0821b39ef4ddd869a063490f0f064.r2.dev/webmailwebsitw.html#suspect@safeonweb.be

Page Load Overview

4.67s
Total Load Time
244 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,438 chars
Detector Agreement:100%

Website Classification

Primary Category

social_media50% confidence
Type: webapp
Method: structural

All Detected Categories

social_media
50%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2162.241.27.10Mumbai, Maharashtra, India
AS46606Unified Layer
2151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.14.95Google · CDNUnited States
AS15169Google LLC
2104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2142.251.127.95Google · CDNUnited States
AS15169Google LLC
189--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13F133B505CF94467828281C87E20162929E28737CA2F4E4472BD47F90FD7FDEDDAB06A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:kB45xRg9F6kOp8zhQWEB45xRg9F6kOp8zhQ61aNEvRuqG:15xRgv6F8QWV5xRgv6F8QyaNEvgqG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:44985:AxWCAwgBIhhUBAxwQCRQXEHiAGdSCDKCHFIAcCwFCUAqYStCOEMiQ4QEAAEC8qylViAAC9JR4AICBUcEQhQwAIjS5CBIgZmS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7ffe7ffffffff
Perceptual Hash:e767666666329898
Difference Hash:4d0c080c00080000
Wavelet Hash:242424243f273f3f
Color Hash:#2d8649

Other Hashes

Crop Resistant:4d0c080c00080000

Scan History

Scan history not available

Unable to load historical scan data