Security Scan Report: pub-dc2e59bc37c14990a4ca3fd1a2e63351.r2.dev

Submitted: Sep 29, 2026, 2:52:09 AMCompleted: Sep 29, 2026, 2:52:43 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Content-free page on a Cloudflare R2 public bucket with one unexplained fetch to an unranked third-party domain. No forms, no malware, no Indicators of Compromise — nothing concrete is malicious, but the page's purpose is unverifiable.

Risk Factors (3)
Opaque, content-free page hosted on cloud storage with no verifiable operator or branding
Outbound fetch to an unranked third-party domain (carelagesjatelierplume.com.ru) with no explainable purpose
Shared-hosting tenant with no attributable domain age or reputation (unranked in Cisco Umbrella)
Safety Factors (6)
No credential or payment forms present (verified: 0 forms, 0 password fields, 0 payment fields)
No Indicators of Compromise matches against the page or its resources
No JavaScript malware patterns (YARA) and no known malicious kits detected
No credential exfiltration or disguised password fields
The 2 Suricata alerts are informational ET INFO notices about the r2.dev bucket domain itself, not malware or phishing signatures
Verdict names no specific threat, and DOM analysis found no password field (real or disguised) or payment field and no other hard signal — elevated score unsupported; risk adjusted from 4 to 4
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'pub-dc2e59bc37c14990a4ca3fd1a2e63351.r2.dev' is registered with subdomain 'pub-dc2e59bc37c14990a4ca3fd1a2e63351'. The registrable portion 'r2' spans 2 characters containing 0 vowels alongside 1 consonant, along with 1 digit. Splitting it apart reveals 2 words: r, 2. The median word length lands at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-dc2e59bc37c14990a4ca3fd1a2e63351.r2.dev/index.html

Page Load Overview

0.91s
Total Load Time
47 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:57%
Script:Latin
Direction:ltr

Detection Details

Text Length:100 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical82% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
82%
adult content
71%
government public service
52%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
42--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T144C1A97024B8213A9347D5A075F15F9D463FC6458B038C3A73BC61E78FCA95C8AAA8D3

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:L+kycSjoFM6gMAVIr+64c/d2E0KhGEID43FNSx:LtbSj2F+VIrqO4ExhSD414x

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5600:EINg2L0RGEAiTRgSCgIAI4KAgAypBBoJIBQMBQIAlAAA5AAKAFAAnxABQGGPAEpSgAFAQAIEACAEEZBzIjDAYBgwLoQFAUQE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6269999663399cc
Difference Hash:0008000c0c000800
Wavelet Hash:03033f27273f0f0f
Color Hash:#936b1f

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data