Security Scan Report: urlshort-linkmu9unjr7t3a7.s2908sytem3.workers.dev

Redirected to:
https://urlshort-linkmu9uwm4tctbb.banksystem.workers.dev/site/n26-uglw...
Submitted: Sep 21, 2026, 6:50:06 AMCompleted: Sep 21, 2026, 6:50:25 AMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 7 HTTP transactions. The main domain is urlshort-linkmu9uwm4tctbb.banksystem.workers.dev and was registered 7 years ago.

Submitted URL: https://urlshort-linkmu9unjr7t3a7.s2908sytem3.workers.dev/0tnngm

Effective URL:

https://urlshort-linkmu9uwm4tctbb.banksystem.workers.dev/site/n26-uglw...
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page impersonating N26 bank on a Cloudflare workers.dev subdomain, using urgency and fake BaFin/deposit-insurance claims to harvest IBAN and personal data. Not affiliated with N26.

Risk Factors (5)
Brand impersonation of N26 on a non-N26, unranked hosting-platform subdomain
Collection of IBAN and full personal/contact details via a spoofed bank form
False legal/regulatory assurances (BaFin supervision, €100,000 deposit insurance) to build trust
Deadline/threat pressure to force victim submission
Cross-domain submission to a second disposable workers.dev host
Domain age information unavailable

Details

Page Title

Dringende Datenverifizierung | N26

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'urlshort-linkmu9unjr7t3a7.s2908sytem3.workers.dev' is registered and includes subdomain 'urlshort-linkmu9unjr7t3a7.s2908sytem3'. Count 7 characters in 'workers' split between 2 vowels and five consonants. Splitting it apart reveals 1 word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://urlshort-linkmu9unjr7t3a7.s2908sytem3.workers.dev/0tnngm

Page Load Overview

1.40s
Total Load Time
154 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:3,790 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking86% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
86%
government public service
73%
documentation technical
73%
adult content
73%
cryptocurrency blockchain
47%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.21.65.106Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.145.35Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
73--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15213D6626EF5602AB413C486BB85772FF6259013DD0A4384F69C4A688FC7FD26D2F748

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:sIJetN3y3gOrAht4lpJLIqBvOBv328hanMG7Cy6x:sIJf+l28hRiz6x

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:45380:yVAEV5mWjVqCIHxQFAzIWBJWE8ICAAgB8Ao5SAX6AIABKhiMASFUhjaKAYIwnDADSBBmBmBMhIPlGAyiOQmnGEHwtAgYkLEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fe968e8f8f9ffff1
Perceptual Hash:bc1664936993699b
Difference Hash:44243c3c3c3ec827
Wavelet Hash:009682878f87fff1
Color Hash:#784f3a

Other Hashes

Crop Resistant:44243c3c3c3ec827

Scan History

Scan history not available

Unable to load historical scan data