Security Scan Report: fc2617cf.4346164a315335d9f00d2c36.workers.dev

Site favicon
Submitted: Aug 27, 2026, 2:50:54 AMCompleted: Aug 27, 2026, 2:54:36 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 86%

8
Risk Score

Analyst-vetted phishing gate kit: this workers.dev page fakes a Cloudflare 'Just a moment' challenge with a hidden cfForm gate that loads a credential page after the fake check. Avoid interaction.

Risk Factors (5)
Fake Cloudflare challenge page impersonating a security check the site does not control
Known phishing kit (turnstile-gate-kit-202609) identified by content anchors and YARA
Self-posting gate form (cfForm / verifyCallback_CF) that conditionally loads a second-stage page
Heavy dynamic code execution (71 eval calls) on a page that only claims to be a security check
Unranked domain on an anonymous instant-hosting subdomain
Domain age information unavailable

Details

Page Title

Just a moment...secondary capture

Scan Type

public

Domain Name Analysis

You're looking at domain 'fc2617cf.4346164a315335d9f00d2c36.workers.dev' on the developer-focused generic top-level domain (.dev); it also runs on subdomain 'fc2617cf.4346164a315335d9f00d2c36'. The second-level label 'workers' is 7 characters long split between 2 vowels and 5 consonants. Segmentation suggests one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://fc2617cf.4346164a315335d9f00d2c36.workers.dev/

Page Load Overview

0.46s
Total Load Time
518 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:200 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical67% confidence
Type: static
Method: ml+structural

All Detected Categories

documentation technical
67%
government public service
63%
blog personal website
53%
news media journalism
49%
adult content
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3188.114.97.3Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
72--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A761963F6A21701AD6F38A7621F163DE3820E108DB03879AEE77A7444ED266A1E1174D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:PzTW4lNvkiWUZhbWYBUO36yKrnVjbv8+qfOcqwFtiGNirSVmu/sC7e4k5:PGeiUXtBUOXanFISch+rSOcg5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3318:ABg5AkABSIIczAEAIIQAIEACAAgAAQ4mgACEEAgACgAYAFIIAkgIhFAgAACABABKABAAIAAEAiMwUgSAAkAEGZEDAAApB0CA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc783c3ffffffe7
Perceptual Hash:b038c3cfc7cc6631
Difference Hash:00181e3600000008
Wavelet Hash:3f07031f3c3c3c00
Color Hash:#74ac53

Other Hashes

Crop Resistant:00181e3600000008

Scan History

Scan history not available

Unable to load historical scan data