Security Scan Report: banshee.retusus.workers.dev

Site favicon
Submitted: Aug 8, 2026, 1:45:08 AMCompleted: Aug 8, 2026, 1:46:15 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is banshee.retusus.workers.dev and was registered NaN years ago.

Submitted URL: https://banshee.retusus.workers.dev/

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Page is a high‑risk phishing site impersonating Apple; do not trust or interact.

Risk Factors
Brand impersonation via favicon
Cloudflare phishing warning page
Unranked domain on a hosting subdomain
High‑confidence phishing label from content analysis
Domain age information unavailable

Details

Primary Scan Blocked — Fallback Capture Shown

The primary scanner could not load this page (possible bot protection). The screenshot and page details shown were captured by a fallback browser that loaded the page successfully.

Page Title

Suspected Phishing | Cloudflare

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

phishing scam

(90%)

Domain Information

You're looking at domain 'banshee.retusus.workers.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'banshee.retusus'. The registrable portion 'workers' spans 7 characters holding two vowels versus 5 consonants. Segmentation suggests one word: workers. Average segment length settles at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://banshee.retusus.workers.dev/

Page Load Overview

0.40s
Total Load Time
6
HTTP Requests
2
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:373 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam90% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
90%
technology software
35%
documentation technical
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6188.114.97.3Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
61--

Page Statistics

6
Requests
2
Unique Domains
38.3 KB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T153814267BAFD103E21A3917266BDB70A35A1C007CAA6499036BCC2750F4AF92AD132C1

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:libDa/D+DMFBzLeiO/tjA2uenRC3vaQxvb0:liPa/SoFnOV3uenM3Cej0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4167:QIAAkrmwDCAAAEUAABAiAgA0gIAUUYQAQQcIACAIDcAAIBAQERAACAiFEAgkAQgCIBBOAwIAAIAQASQBYRFgAACKAAAARQAk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc7c7ffffffff
Perceptual Hash:b331cccccc633333
Difference Hash:00180c1400000000
Wavelet Hash:f0d0c0ccf0f0f0f0
Color Hash:#ac8b53

Other Hashes

Crop Resistant:00180c1400000000

Scan History

Scan history not available

Unable to load historical scan data