Security Scan Report: pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev

Site favicon
Submitted: Oct 4, 2026, 12:53:53 AMCompleted: Oct 4, 2026, 12:54:29 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 82%

9
Risk Score

Cloned 网易企业邮箱 webmail login served from a Cloudflare R2 bucket instead of NetEase's official domain, with an email+password capture form — a credential-phishing page. Do not enter credentials.

Risk Factors (4)
Brand impersonation of NetEase Enterprise Email on a non-official domain
Credential-harvesting login form (username + password) on cloud-storage hosting
Unranked/unknown-reputation host claiming to be a major brand login page
Page age indeterminate — hosted on a multi-tenant R2 public bucket
Domain age information unavailable

Details

Page Title

网易企业邮箱 - 登录入口

Scan Type

public

Domain Name Analysis

The domain name 'pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-d32e1723091e4c74b19f3caea6a4ed0a'. Its registrable label 'r2' stretches across 2 characters holding zero vowels versus one consonant; bonus characters include one digit. Breaking it apart gives 2 words: r, 2. Median word length is one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev/qiye-revised/index.html

Page Load Overview

0.96s
Total Load Time
227 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:13 chars
Detector Agreement:0%

Website Classification

Primary Category

entertainment media71% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

entertainment media
71%
government public service
56%
healthcare medical
53%
finance banking
49%
cryptocurrency blockchain
48%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1103.126.92.250Hong Kong
AS137263NETEASE HONG KONG LIMITED
1104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1103.126.92.249Hong Kong
AS137263NETEASE HONG KONG LIMITED
66--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17D61B5957CA963A53AB301F420F7969C155DC1027708C840F47CB5C9AF95FC9B533568

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:qjqeDDhfHHBfKqBRdQHVK1CUqo+yWwdxD1I:4DVntz0VK1CUqoFm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3356:AgAkMAAMDMEQNAAxMIoEAhAAAICQQIAACBEIEQCEAAAogIQAgAQEQKCAFQCgABABAAARAgCUBoYAQCAIAAgDIUgAYnAUCQQg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:18183838180000ff
Perceptual Hash:c959b636e067a626
Difference Hash:b2f2f2f2b20d1080
Wavelet Hash:1c7c7c7cfc0000ff
Color Hash:#5dbf40

Scan History

Scan history not available

Unable to load historical scan data