Security Scan Report: pub-9204f20e06e047fc844db30aa53e5d5c.r2.dev

Submitted: Sep 17, 2026, 5:50:18 AMCompleted: Sep 17, 2026, 5:50:39 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Empty page on a Cloudflare R2 public bucket with a suspicious .moscow external reference. No forms, no Indicators of Compromise, no malware — but the staged, unreputable setup warrants caution.

Risk Factors (2)
Empty/staged page served from a public cloud-storage bucket rather than a business's own domain
External reference to a suspicious .moscow domain with currency-themed naming
Safety Factors (5)
No forms of any kind — zero password, zero payment, zero email fields
No Indicators of Compromise matched against the page or its resources
No JavaScript malware (YARA) patterns and no behavioral/credential-exfiltration signals
Suricata alerts are informational R2-bucket observations (ET INFO, MEDIUM), not malware or phishing detections
No brand impersonation detected
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'pub-9204f20e06e047fc844db30aa53e5d5c.r2.dev' is registered, featuring subdomain 'pub-9204f20e06e047fc844db30aa53e5d5c'. Count 2 characters in 'r2' split between zero vowels and 1 consonant, along with one digit. Tokenizing the label suggests two words: r, 2. The median word length lands at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-9204f20e06e047fc844db30aa53e5d5c.r2.dev/index.html

Page Load Overview

0.98s
Total Load Time
47 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

0
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
43--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T184D02E93E818C92C72A1E9083CF0F71C0A7C981822528A8A5BC8027F08C43C988C6508

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:qzxJfAbpli7vuwt1cFFoOvjT08N5vLL37mNVuB9d:kx2y7W+1c/Lg8N5TeNVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:f99a383f949f73b612692ed6a8612913

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6269999663399cc
Difference Hash:0008000c0c000800
Wavelet Hash:f0f0f8e0e0f0f0f0
Color Hash:#e0e06c

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data