Security Scan Report: pub-408a43e5a2f24bbca8411418be6cccb6.r2.dev

Submitted: Sep 26, 2026, 11:50:37 PMCompleted: Sep 26, 2026, 11:51:33 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Fake 'Ledger Live' page on a Cloudflare R2 bucket harvests 12/24-word wallet recovery seed phrases and PINs, exfiltrating them via cross-origin POST. Definitive crypto phishing — never enter a seed phrase.

Risk Factors (5)
Brand impersonation of Ledger (a DIFFERENT entity) on an unrelated r2.dev bucket domain
Credential (seed phrase / wallet recovery) harvesting forms with 12- and 24-word inputs
Cross-origin POST of captured data to veryprettyimmortalgod123.publicvm.com (external, unrelated host)
Obfuscated JS: inline eval() and encode/decode functions typical of phishing kits
Single-source phishing threat-intel match on the primary domain
Domain age information unavailable

Details

Page Title

Ledger Live

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'pub-408a43e5a2f24bbca8411418be6cccb6.r2.dev' is registered; it also runs on subdomain 'pub-408a43e5a2f24bbca8411418be6cccb6'. The second-level label 'r2' is 2 characters long with zero vowels and one consonant, notching 1 digit. Splitting it apart reveals 2 words: r, 2. Expect one character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-408a43e5a2f24bbca8411418be6cccb6.r2.dev/z14.html

Page Load Overview

2.90s
Total Load Time
579 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,058 chars
Detector Agreement:50%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
235.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2142.251.20.95Google · CDNUnited States
AS15169Google LLC
2151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
263.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
197--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12D846CA1E2674B6DB33326141FADD2217A55530FE3C1C8A53A4CB8D09F8FAA0C2F5759

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:HznXEb15YkWMRUaaMdIm86S6nQm86S6ntm86S6n+m86S6nuVuryrl:HznXEh5YkWMRUaaMd18E8N8m8tVR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:379016:YBCJNEVhSFuIYKQchwYKkvCmABJMAOJwQCMTgeApgAMUHytAAC3EAspgBQDgjEBOjFBBJUElEZAgEkiPwJmCAgNMAQABESQl

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000001818000000
Perceptual Hash:993366cc993366cc
Difference Hash:0000003030000000
Wavelet Hash:0000081818180000
Color Hash:#86492d

Other Hashes

Crop Resistant:0000003030000000

Scan History

Scan history not available

Unable to load historical scan data