Security Scan Report: pub-b325673d26f6495d8c9a34b45cc26df4.r2.dev

Submitted: Sep 30, 2026, 5:53:56 AMCompleted: Sep 30, 2026, 5:54:36 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake cPanel 'Webmail Login' hosted on a Cloudflare R2 bucket that posts entered email/password cross-origin to an unrelated domain (bi-lectric.co.za), matching a high-severity phishing IDS alert. Do not enter credentials.

Risk Factors (5)
Credential harvesting login form (1 password field, 3 email/username fields) on cloud-storage hosting
Cross-origin credential POST to bi-lectric.co.za/mail/form-loaded.php (external, unrelated domain)
Impersonation of cPanel Webmail branding on a non-official domain
Network IDS high-severity phishing alert
Cloudflare R2 public bucket used to host a phishing landing page
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Domain Name Analysis

Domain 'pub-b325673d26f6495d8c9a34b45cc26df4.r2.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'pub-b325673d26f6495d8c9a34b45cc26df4'. The core label 'r2' covers 2 characters containing 0 vowels alongside one consonant; it also includes one digit. Segmentation suggests two words: r, 2. Expect 1 character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-b325673d26f6495d8c9a34b45cc26df4.r2.dev/webmail.html

Page Load Overview

5.40s
Total Load Time
230 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:43%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,245 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

social_media50% confidence
Type: webapp
Method: structural

All Detected Categories

social_media
50%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1162.241.27.10Mumbai, Maharashtra, India
AS46606Unified Layer
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.0.22Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2111--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15B72730268E91463018664DCBDA5162E1E96E327860F0E44F17F4BE55FE7FDEEC8704A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:WyEiUELD/ZmXg8oWlleLOSFSF+ct+KqD+lVKMENEvmUGyeEUQpxvnKc:iiUWD/ZmXg8cOM+l6NEvRFznKc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17341:AsREbysECSAxJNABQEkAWZuW1ChHwEJYUxCOSSAFEUIgKGWLMgAIJKCSSSDIgRXEhDooEhYECkQYiN4XDQLAAgCAAoAXFvU2

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7ffffffff
Perceptual Hash:e766cccc66663388
Difference Hash:0c0c0c0c00080000
Wavelet Hash:20202424e4e4fcfc
Color Hash:#732d86

Other Hashes

Crop Resistant:0c0c0c0c00080000

Scan History

Scan history not available

Unable to load historical scan data