Security Scan Report: 94o3v-9qe-6v45-u60hv-21-09-2026-hh.pages.dev

Site favicon
Submitted: Sep 22, 2026, 12:45:10 PMCompleted: Sep 22, 2026, 12:45:33 PMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 7 HTTP transactions. The main domain is 94o3v-9qe-6v45-u60hv-21-09-2026-hh.pages.dev and was registered 9 years ago.

Submitted URL: https://94o3v-9qe-6v45-u60hv-21-09-2026-hh.pages.dev/qaz-wsx-edc-rfv?welcome=1668194120152630&token248=1668194120152630&name_token136=Caracol%20Music

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Analyst-vetted Meta 'Page Appeal' credential-phishing kit impersonating Meta Business on a random pages.dev subdomain, using a fake 48-hour suspension threat to harvest account appeals. Report and avoid.

Risk Factors (5)
Impersonation of Meta/Facebook Business brand on an unrelated pages.dev subdomain
Known malicious phishing kit identified by the kit roster
Urgency/deadline coercion (48-hour suspension threat) to force credential submission
Obfuscated cloaking behaviour in the deployed bundle
Unranked domain on a free hosting namespace with unknown page creation date
Domain age information unavailable

Details

Page Title

Meta for Business | Page Appeal

Scan Type

public

Domain Name Analysis

The domain name '94o3v-9qe-6v45-u60hv-21-09-2026-hh.pages.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain '94o3v-9qe-6v45-u60hv-21-09-2026-hh'. The core label 'pages' covers 5 characters holding two vowels versus 3 consonants. Splitting it apart reveals 1 word: pages. The median word length lands at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://94o3v-9qe-6v45-u60hv-21-09-2026-hh.pages.dev/qaz-wsx-edc-rfv?welcome=1668194120152630&token248=1668194120152630&name_token136=Caracol%20Music

Page Load Overview

0.88s
Total Load Time
214 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,774 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network88% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
88%
technology software
59%
entertainment media
50%
documentation technical
47%
government public service
46%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.26.1.100Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
73--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CC017B13CC10D48EA27093ABFDB2B16CC549B90DAAA27C50B4D615DB4AE4BE1CC67952

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hR0n56M8C2Zn816pX8VGuaXiKMci/CrC+qrVe1yTG7faKj2a:hR056tC3spXoGa3WC+qrVqyC75j2a

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:707:AAAAAAAAAACIARAAAAgAAAABAAAAAACAAAABAAAIAAAgAQIAAAAAAAAABAAAAAAAAAAAgAAAAAAAAAAAAAAAEAAgAAAQAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e3f3fffff0f0f0f0
Perceptual Hash:ecb96564b1b36249
Difference Hash:0307033024242424
Wavelet Hash:c1c1e1fff0f0d0d0
Color Hash:#1f9327

Other Hashes

Crop Resistant:0307033024242424

Scan History

Scan history not available

Unable to load historical scan data