Security Scan Report: mn3w-fny9-jyay.dibafef289.workers.dev

Site favicon
Submitted: Sep 5, 2026, 12:45:18 AMCompleted: Sep 5, 2026, 12:47:40 AMpubliccompleted

This website contacted 9 IPs in 1 country across 5 domains to perform 12 HTTP transactions. The main domain is mn3w-fny9-jyay.dibafef289.workers.dev and was registered 29 years ago.

Submitted URL: https://mn3w-fny9-jyay.dibafef289.workers.dev/3410deffe3b7ed9e?email=elynx@7c252ba54cf7c952cfe9e66cb56a0aefd4e7.net

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Page shows DocuSign brand impersonation with phishing indicators and high‑severity IDS alerts, indicating a credential phishing threat.

Risk Factors
Phishing IDS alerts
DevTools/right‑click blocking
Brand impersonation of DocuSign on unranked subdomain
Free hosting subdomain (workers.dev) with unknown age
Domain age information unavailable

Details

Page Title

DocuSign - Review Document

Scan Type

public

Domain Name Analysis

The domain name 'mn3w-fny9-jyay.dibafef289.workers.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'mn3w-fny9-jyay.dibafef289'. The core label 'workers' covers 7 characters with two vowels and five consonants. Breaking it apart gives 1 word: workers. Expect seven characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mn3w-fny9-jyay.dibafef289.workers.dev/3410deffe3b7ed9e?email=elynx@7c252ba54cf7c952cfe9e66cb56a0aefd4e7.net

Page Load Overview

1.52s
Total Load Time
189 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:534 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software60% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
60%
documentation technical
50%
government public service
36%
corporate business
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.67.167.51Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.154.119Google · CDNUnited States
AS15169Google LLC
1142.251.127.95Google · CDNUnited States
AS15169Google LLC
1142.251.151.119Google · CDNUnited States
AS15169Google LLC
1104.21.16.95Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1142.251.13.94Google · CDNUnited States
AS15169Google LLC
134.236.97.70Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1142.251.157.119Google · CDNUnited States
AS15169Google LLC
129--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12B62AEB1AAB36E681A3848443FFDFB1C18B86440E855458CFE384DC9A980C4F7E4ED5D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:vQ4MTlRvJ1UtNQCT356x/nJZVR+gHThVgToW2:vQ4cllUtNQCT3E/nLPXhSToW2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15236:loj0grDEEhAKJCKIR0GAgFyGRKIARt4AgTDjzBIy9CAhEI7KMpAAJoAFCAGCoEjAMCIgFfjkECwQKS1J6YUSMEgAMJOCAwq5

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:88786370dcf2d8f8
Difference Hash:33cfb2b2b2b2cdf3
Wavelet Hash:03031f1b1b1f0f3f
Color Hash:#53ac7d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data