Security Scan Report: pub-4e0d515d9c79417e8b4042dfa120d149.r2.dev

Site favicon
Submitted: Jul 9, 2026, 8:51:17 PMCompleted: Jul 9, 2026, 8:53:18 PMpubliccompleted

This website contacted 2 IPs in 1 country across 3 domains to perform 3 HTTP transactions. The main domain is pub-4e0d515d9c79417e8b4042dfa120d149.r2.dev and was registered 4 years 1 month ago.

Submitted URL: https://pub-4e0d515d9c79417e8b4042dfa120d149.r2.dev/shyfacewebnnf.html?koiclid=DtsiGAESnl

AI Security Verdict

Confirmed Scam

Confidence: 94%

9
Risk Score

Page harvests Spectrum credentials and sends them to an external server; confirmed phishing.

Risk Factors (5)
Credential exfiltration to external server
Brand impersonation of a major ISP
Unranked domain claiming to be official service
Right‑click blocking (defense evasion)
Cross‑origin request to unknown external domain
Domain age information unavailable

Details

Page Title

Login TWC & Roadrunner RR Email | Spectrum Webmail

Scan Type

public

Domain Name Analysis

The domain 'pub-4e0d515d9c79417e8b4042dfa120d149.r2.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'pub-4e0d515d9c79417e8b4042dfa120d149'. The core label 'r2' covers 2 characters containing zero vowels alongside 1 consonant, notching one digit. Breaking it apart gives two words: r, 2. The median word length lands at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-4e0d515d9c79417e8b4042dfa120d149.r2.dev/shyfacewebnnf.html?koiclid=DtsiGAESnl

Page Load Overview

6.24s
Total Load Time
49 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:745 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media55% confidence
Type: static
Method: ml+structural

All Detected Categories

entertainment media
55%
technology software
38%
corporate business
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
32--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13F62A6BB15B72826754390AC3BA75701321AE0031947D9593FEC5B9C9F8AF8CA9237CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:QSq9GYz4/skzZxz7pAJ6hh3+Zh0acQkGY:TYz4/rlH3z

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15447:g8RksjECgBZsEHJMAy2QCIHBQU/kMZcVNZKoZAoykSgYFACyxHQQRhVakgQdRV6gQAGAKKKAJsaZwwRjJAIMmALMiAxAAJsC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffe7ffff00
Perceptual Hash:b3b14ce633990ce6
Difference Hash:88100c484d080060
Wavelet Hash:00fbe7e7e0e00000
Color Hash:#ac5384

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data