Security Scan Report: pub-6a3d146cbfec43ec9112d67612054c37.r2.dev

Submitted: Sep 29, 2026, 10:52:35 AMCompleted: Sep 29, 2026, 10:53:12 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Empty 'Webmail - Login' credential form hosted on an anonymous Cloudflare R2 bucket, unbranded and unranked — a classic credential-harvesting page; do not enter any email or password.

Risk Factors (5)
Credential (email + password) form on shared cloud-storage hosting
No branding or identity disclosure — page pretends to be a 'Webmail' service
Hosting subdomain (r2.dev bucket) unrelated to any webmail provider
Unranked domain with no reputation, actual page age unknown
Unrelated external domain (alphatrade-options.com) linked from a login page
Domain age information unavailable

Details

Page Title

Webmail - Login

Scan Type

public

Domain Name Analysis

Domain 'pub-6a3d146cbfec43ec9112d67612054c37.r2.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-6a3d146cbfec43ec9112d67612054c37'. The second-level label 'r2' is 2 characters long containing 0 vowels alongside one consonant, notching one digit. Splitting it apart reveals 2 words: r, 2. Median word length is one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-6a3d146cbfec43ec9112d67612054c37.r2.dev/grace-domain.html

Page Load Overview

1.61s
Total Load Time
56 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:71 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism56% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

news media journalism
56%
government public service
49%
technology software
43%
healthcare medical
41%
documentation technical
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0172.217.118.4Google · CDNUnited States
AS15169Google LLC
0208.91.114.103Langley, British Columbia, Canada
AS40934Fortinet Inc.
0156.226.121.244Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
0104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0172.217.112.4Google · CDNUnited States
AS15169Google LLC
610--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10592E7015DF108021343886ABF536546F552C807AA4FCD4CBAACAF98EF85E63D8637BD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:r+RFYLaAyIF7/7lxYtO2bjGJzrd+rI0att8+TL14IHYzUChzc7:r+RFcVyIFjkBbjIrsIQhlc7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:20260:GEMEBBYGGKhviCAASDkMCDBPigABiEs6QQhFDwENexhkMXCyBQJfJWEACgUIYMEwOgkbWTZL4DCGCAgkDDBQ2gADCFVQGhFw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c1c0810000000
Perceptual Hash:d999666633393166
Difference Hash:0a22525226020202
Wavelet Hash:00382838f2f2f2f2
Color Hash:#405bbf

Other Hashes

Crop Resistant:0a22525226020202

Scan History

Scan history not available

Unable to load historical scan data