Security Scan Report: ppap-bhb.pages.dev

Redirected to: https://ppap-bhb.pages.dev/

Site favicon
Submitted: Feb 4, 2026, 7:33:10 PMCompleted: Feb 4, 2026, 7:34:25 PMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 2 countries across 8 domains to perform 17 HTTP transactions. The main domain is ppap-bhb.pages.dev and was registered NaN years ago.

Submitted URL: http://ppap-bhb.pages.dev/

Effective URL: https://ppap-bhb.pages.dev/Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

High‑risk phishing site impersonating GitHub on a pages.dev subdomain

Risk Factors
Brand impersonation on an unranked subdomain
Subdomain on a generic hosting platform with unknown creation date
Domain age unknown (potentially newly registered)
Unranked domain in Cisco Umbrella while claiming a major brand
Domain age information unavailable

Details

Page Title

Cloudflare Country-Specific IP Filter

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

technology software

(41%)

Domain Information

Within the developer-focused generic top-level domain (.dev), 'ppap-bhb.pages.dev' is registered and includes subdomain 'ppap-bhb'. The core label 'pages' covers 5 characters with two vowels and three consonants. It segments into 1 word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://ppap-bhb.pages.dev/

Page Load Overview

8.05s
Total Load Time
17
HTTP Requests
8
Domains
240 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:581 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
adult content
36%
documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3188.114.97.3United States
AS13335Cloudflare, Inc.
2185.199.110.133United States
AS54113Fastly, Inc.
2216.58.206.74Germany
2104.26.2.143United States
AS13335Cloudflare, Inc.
2142.251.141.67GermanyUnknown
2104.18.1.22United States
AS13335Cloudflare, Inc.
2104.16.123.96GermanyUnknown
2140.82.121.4GermanyUnknown
178--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18D63D81522B1083E1D6340D9F286BFA9B27D72C3EE1A917DB16C41125FDADB09DDF288

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:zX9CX7Gehn/HXvLR9at+WbQe1fZgaHfrTJwHtwrnm/J3z:j9CX7Geh//ugyfVkz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:68320:GAggHAiEpULEIQJ8ShQlAClQAQACGTRwbAAQMnAAMURUWNhMKEjRABiMUSiAUVtFSg8DEOE7KzARQHgACAqFCCME+BYsioBS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:feffffffffc3c3ff
Perceptual Hash:f1cec630c66338c7
Difference Hash:60320616409e0a4a
Wavelet Hash:3efae4c4c0c083fd
Color Hash:#e06c92

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data