Security Scan Report: test2401ccc.jhutov0c.workers.dev

Site favicon
Submitted: Aug 18, 2026, 5:09:42 AMCompleted: Aug 18, 2026, 5:10:49 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 72%

3
Risk Score

The site mimics a government brand on an unknown-age workers.dev subdomain with obfuscated scripts but no credential collection; treat as moderate risk.

Risk Factors
Brand impersonation without matching domain
Unknown creation date of subdomain on hosting platform
Highly obfuscated JavaScript
Safety Factors
No credential or payment collection forms
No Indicators of Compromise or malware YARA matches
No network IDS alerts
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 3
Domain age information unavailable

Details

Page Title

Origin DNS error | mail.gov.cn | Cloudflare

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'test2401ccc.jhutov0c.workers.dev' is registered and includes subdomain 'test2401ccc.jhutov0c'. The core label 'workers' covers 7 characters with two vowels and five consonants. Breaking it apart gives one word: workers. The median word length lands at 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://test2401ccc.jhutov0c.workers.dev/

Page Load Overview

0.46s
Total Load Time
14 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:914 chars
Detector Agreement:67%

Website Classification

Primary Category

documentation technical74% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
74%
government public service
71%
technology software
70%
cryptocurrency blockchain
59%
news media journalism
49%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.21.67.23Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.31.78Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
62--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18D02B663F0F855290043C35675B9BB2D7926A01B9BB108E57E5E42726F8EF93FD02388

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:lna/daa7lOzz1zafgP60ZnkvieJi/pVsSsIsc4s4IRsANrMACML:pa/EgO0fwRZnkvieCE8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8977:WEIJgAUAGqQQBIMLEJvIPABQRQAcEoQAQWQCcYm0pQQOgDIIYVUIDASIqQBPAUsIi7K0YREQWLOEUICLhbZoAQpGkyQ2iWIA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c7cfcfcfcfcfe7ff
Perceptual Hash:b838c7711c673339
Difference Hash:1e341838181c0e14
Wavelet Hash:838f8f878c84c0fc
Color Hash:#e08f6c

Other Hashes

Crop Resistant:1e341838181c0e14

Scan History

Scan history not available

Unable to load historical scan data