Security Scan Report: pub-f6267a1907b44a078354e073bd286e20.r2.dev

Site favicon
Submitted: Jul 12, 2026, 4:51:48 AMCompleted: Jul 12, 2026, 4:53:21 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 7 domains to perform 2 HTTP transactions. The main domain is pub-f6267a1907b44a078354e073bd286e20.r2.dev and was registered NaN years ago.

Submitted URL: https://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.html

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

The site impersonates The Courier Guy and solicits payment, indicating a high‑risk phishing scam.

Risk Factors
Brand impersonation of a well‑known courier service
Payment request on a non‑official domain
Unranked domain with no reputation
Domain age information unavailable

Details

Page Title

The Courier Guy

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(56%)

Domain Information

You're looking at domain 'pub-f6267a1907b44a078354e073bd286e20.r2.dev' on the developer-focused generic top-level domain (.dev) with subdomain 'pub-f6267a1907b44a078354e073bd286e20'. Count 2 characters in 'r2' with zero vowels and one consonant, plus one digit. Segmentation suggests two words: r, 2. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-f6267a1907b44a078354e073bd286e20.r2.dev/Cg/index.html

Page Load Overview

4.46s
Total Load Time
66
HTTP Requests
27
Domains
2.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:643 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking56% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
56%
government public service
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1218.66.102.51Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
9104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
9142.251.13.97Google · CDNUnited States
AS15169Google LLC
9157.240.0.6Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
965.9.175.27Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
9142.250.154.95Google · CDNUnited States
AS15169Google LLC
923.36.163.242Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
667--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19A04D69362A029FA1B338137538E99C8B14C4CD5B913E9E6F5DE98490BC96FD0D13B27

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:PJ/FVuUmSmemSm8mSmRmSmNXmSm4mSmkmSmewspOO7BWuS5E/TdJlf5fef9fgf+a:lbh7BW6Y0wB1swCP7xr

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:177408:aoCaABBsw9hAZCKsmAyFIEAJAUoVWCUhKqORHI0ADEwmCoANRYgsXAsclkMQlZxCgEAQCTmKAdcFNQggSJahgshAULEdAhAC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:07bbb9c989f3e7ff
Perceptual Hash:bc09863419e7cf3c
Difference Hash:da77639b33274c12
Wavelet Hash:02b381c888f9e3ff
Color Hash:#d2ad79

Other Hashes

Crop Resistant:da77639b33274c12

Scan History

Scan history not available

Unable to load historical scan data