Security Scan Report: logon-dp3qrium4uhq.edgeone.dev

Submitted: Sep 24, 2026, 12:45:35 PMCompleted: Sep 24, 2026, 12:47:12 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 70%

7
Risk Score

Unbranded email/password login on a random-string edgeone.dev subdomain of unknown age, with hidden form fields and IDS hits for an actor-abused service — a credential-harvesting login page pattern. Do not enter credentials.

Risk Factors (4)
Credential login form capturing email and password on a suspicious, unranked random-subdomain host
Hosted on a free instant-subdomain platform where the tenant could have been created minutes ago
Hidden non-standard form fields (pdf1, address, email, type) suggesting a kit/template
IDS alerts for a commonly actor-abused service (image.thum.io)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain 'logon-dp3qrium4uhq.edgeone.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'logon-dp3qrium4uhq'. Its registrable label 'edgeone' stretches across 7 characters containing four vowels alongside three consonants. Word splitting yields two words: edge, one. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://logon-dp3qrium4uhq.edgeone.dev/

Page Load Overview

2.15s
Total Load Time
371 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:已下架
Text Length:219 chars
Detector Agreement:100%
Language mismatch: Declared as 已下架 but detected as en

Website Classification

Primary Category

adult content29% confidence
Type: webapp
Method: ml+structural

All Detected Categories

adult content
29%
news media journalism
29%
finance banking
28%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1543.174.246.29Singapore
0151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.14.95Google · CDNUnited States
AS15169Google LLC
0142.251.13.95Google · CDNUnited States
AS15169Google LLC
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
043.174.247.29Singapore
0151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1516--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12FE02683ED09886FE1A0CB621AD1F01EC665F96863508D98CCEA05BA2C6678A44E3C58

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:q9hqrACYUX3SwfAbpli7vi1AUvhI+Pf8Wm5tvlHT8NWQAlKPUQyrNVuB9d:PAoXi5y7a1Hma8j5t9z8NWQCUURNVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:40dca5d15048870289b0fb217e34c133

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:9999666666333399
Difference Hash:4cb2b2b2b24c3000
Wavelet Hash:3c3c3c3c38303030
Color Hash:#784f3a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data