Security Scan Report: pub-d16a96460f8d4cf4816cfaf14aa978cd.r2.dev

Submitted: Sep 30, 2026, 10:52:20 AMCompleted: Sep 30, 2026, 10:53:13 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Roster-anchored YARA hit for the Self-hosted Turnstile gate phishing kit: a hidden base64 next-stage URL plus a cross-origin sc.php loader on an anonymous r2.dev bucket. Treat as an active phishing gate.

Risk Factors (5)
Known malicious phishing-kit loader identified by native YARA rule (Turnstile gate kit, family turnstile-gate-kit-202609)
Hidden base64-encoded next-stage URL (b64u) used to chain the victim to a further phishing page
Third-party cross-origin script from sc.php on an unrelated domain, characteristic of a self-hosted gate/redirect kit
Anonymous object-storage hosting on a public r2.dev bucket with no attribution
Interstitial 'verifying' gate designed to filter bots and cloak the real landing page from scanners
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain 'pub-d16a96460f8d4cf4816cfaf14aa978cd.r2.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'pub-d16a96460f8d4cf4816cfaf14aa978cd'. Its registrable label 'r2' stretches across 2 characters split between 0 vowels and one consonant, notching one digit. Breaking it apart gives two words: r, 2. Expect 1 character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-d16a96460f8d4cf4816cfaf14aa978cd.r2.dev/spainert4567.html

Page Load Overview

0.94s
Total Load Time
55 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:74%
Script:Latin
Direction:ltr

Detection Details

Text Length:28 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1192.185.140.71Ashburn, Virginia, United States
AS31898Oracle Corporation
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
54--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13101F4C3A515CD040EC3D9F026A1A21D041AD958DBD6D9472ED9032F99DAEE98D645CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:kx2REXy7iLHskwGWGJPvKNGexV/mgKpOo7DzBkCuoerpecSalih9CnuC1gFHeG:kcACMWoXKVV/qhFuJk1alihEnuAG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:680:AAAAAAAAAAAAAAAAEAAAAAAAAAACBgABAAAAABEAAAAAAAAAAAAAgAICCAAAAgAAAAAAAAAgAAAAAAAAAAAIIAAAACAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:b323cccc3333cccc
Difference Hash:0000000808000000
Wavelet Hash:f0f0d8c0e4fcf0f0
Color Hash:#785b3a

Other Hashes

Crop Resistant:0000000808000000

Scan History

Scan history not available

Unable to load historical scan data