Security Scan Report: wetransfer-east856-dppejjz76yzz.edgeone.dev

Redirected to:
https://wetransfer-east856-dppejjz76yzz.edgeone.dev/
Site favicon
Submitted: Sep 13, 2026, 12:45:27 AMCompleted: Sep 13, 2026, 12:47:01 AMpubliccompleted

This website contacted 3 IPs in 3 countries across 3 domains to perform 20 HTTP transactions. The main domain is wetransfer-east856-dppejjz76yzz.edgeone.dev and was registered 4 months ago.

Submitted URL: http://wetransfer-east856-dppejjz76yzz.edgeone.dev/

Effective URL:

https://wetransfer-east856-dppejjz76yzz.edgeone.dev/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake WeTransfer page on a free-hosting subdomain impersonating the brand and harvesting email/password, submitting credentials cross-origin to a domain flagged as asyncrat malware. Confirmed phishing.

Risk Factors
Brand impersonation of WeTransfer on a mismatched free-hosting subdomain (edgeone.dev) that is not WeTransfer's official domain
Login form harvesting an email address and password
Credential-bearing submission routed cross-origin to pl.tjadae.net/confirm.php, a domain reported as asyncrat malware
ET PHISHING mirrored-website IDS alerts
Domain unranked in Cisco Umbrella with no legitimate reputation; hosting subdomain creation date unknown
Lure content mimicking a business email thread with fake attachments (PDF/ZIP/MP4)
Domain age information unavailable

Details

Page Title

WeTransfer

Scan Type

public

Domain Name Analysis

You're looking at domain 'wetransfer-east856-dppejjz76yzz.edgeone.dev' on the developer-focused generic top-level domain (.dev) with subdomain 'wetransfer-east856-dppejjz76yzz'. Its registrable label 'edgeone' stretches across 7 characters split between 4 vowels and three consonants. Segmentation suggests 2 words: edge, one. The median word length lands at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://wetransfer-east856-dppejjz76yzz.edgeone.dev/

Page Load Overview

7.00s
Total Load Time
973 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:473 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing54% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

download file sharing
54%
technology software
43%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8212.227.90.29Spain
AS8560IONOS SE
643.174.247.29Singapore
663.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
203--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10AC154B39C8B14067602B1746BF6BA8C8215D517964ACD287EDC2264EFC2B4098E7B6D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:R+o58MTWXKCJyW/Oj7i3beWHiOTwvoGowvcDr8SRu+qdJv1W1G7K3Vd0lmbT:Rp58MTW6+yWH37Himwvpow0Dr8SRuF3A

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6006:AgDECUiSSQIBAGQyRQKKgQRQAEhDQI7QwwRAIjAjdCES/xBBgMAJtCAiEQAIECAZYIAyIAIUpBAACDEQNEMEogDI5Mo0EAMJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:01c0c0c0c0c00000
Perceptual Hash:f8e8070baa0bf8f8
Difference Hash:432021a0a0a04000
Wavelet Hash:b1f0f0f0f0f0f0f0
Color Hash:#937e1f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data