Security Scan Report: pub-a9e0176a1d2242e8a8d96f158d08c62b.r2.dev

Submitted: Sep 30, 2026, 7:53:28 AMCompleted: Sep 30, 2026, 7:54:19 AMpubliccompleted

This website contacted 4 IPs in 1 country across 3 domains to perform 5 HTTP transactions. The main domain is pub-a9e0176a1d2242e8a8d96f158d08c62b.r2.dev and was registered 17 years ago.

Submitted URL: https://pub-a9e0176a1d2242e8a8d96f158d08c62b.r2.dev/traffictacticsdexcnancncayhssncnanxndbndnx.html

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Anonymous r2.dev bucket serving a known Turnstile-gate phishing kit ('Verifying site connection...' loader with a hidden base64 next-stage URL). No forms here, but it is a gate to malware/phishing — avoid and report.

Risk Factors (5)
Known malicious Turnstile-gate phishing kit identified by YARA content anchor (HIGH phishing, analyst-vetted roster)
Fake 'Verifying site connection...' human-verification interstitial used as a gate to obscure and distribute a next-stage payload
Hosted on an anonymous public R2 bucket (r2.dev) with no attributable ownership
Domain is unranked/not in Cisco Umbrella top 1M
Obfuscated loader design (base64-encoded next-stage URL, cross-origin sc.php loader path)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'pub-a9e0176a1d2242e8a8d96f158d08c62b.r2.dev' is registered with subdomain 'pub-a9e0176a1d2242e8a8d96f158d08c62b'. The core label 'r2' covers 2 characters containing 0 vowels alongside 1 consonant, plus 1 digit. Tokenizing the label suggests two words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-a9e0176a1d2242e8a8d96f158d08c62b.r2.dev/traffictacticsdexcnancncayhssncnanxndbndnx.html

Page Load Overview

0.60s
Total Load Time
55 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:74%
Script:Latin
Direction:ltr

Detection Details

Text Length:28 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
54--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DA0188C3F515CC180D8388F01F70520D141ACA48D7C58D461ED6422FD4CEBDD4E6168C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:kx2REXy7iLHskwGWGJPvKNGexV/mgKpOo7DzBkCuoerpejgLEDuMCVrZeG8eG:kcACMWoXKVV/qhFuJknuMyZpG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:687:AAAEAAAAAAAAAEAAAAAAAAAAAAACBkAAAAAAABAAAAAAAAAAAAAAgAICCAAAAgAAAAAAAAAgAAAACAAAAAAAIACAAAAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:b323cccc3333cccc
Difference Hash:0000000808000000
Wavelet Hash:f0f0d8c0e4fcf0f0
Color Hash:#936b1f

Other Hashes

Crop Resistant:0000000808000000

Scan History

Scan history not available

Unable to load historical scan data