Security Scan Report: dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev

Submitted: Sep 13, 2026, 12:45:29 PMCompleted: Sep 13, 2026, 12:46:14 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Spotify phishing kit on a disposable edgeone.dev subdomain that exfiltrates login credentials to a Telegram endpoint and also harvests card and 2FA data; blocks DevTools to evade analysis.

Risk Factors (6)
Credential exfiltration to external cross-origin endpoint (Telegram via Cloudflare Workers)
Brand impersonation of Spotify on a non-official domain
Payment card harvesting fields (card number, expiry, CVV, cardholder name)
Anti-analysis: DevTools and right-click blocking
Unknown-age free hosting-platform subdomain
Multi-step fake verification flow requesting SMS/2FA codes
Domain age information unavailable

Details

Page Title

spotify

Scan Type

public

Domain Name Analysis

You're looking at domain 'dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev' on the developer-focused generic top-level domain (.dev) with subdomain 'dead-coffee-vczxixdn-dpwj3cuq93cf'. Count 7 characters in 'edgeone' holding four vowels versus three consonants. Breaking it apart gives 2 words: edge, one. The median word length lands at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev/

Page Load Overview

7.03s
Total Load Time
267 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,730 chars
Detector Agreement:67%

Website Classification

Primary Category

entertainment media33% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.43.142.5United Kingdom
AS16276OVH SAS
143.174.246.29Singapore
145.43.142.7United Kingdom
AS16276OVH SAS
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.43.142.4United Kingdom
AS16276OVH SAS
145.43.142.8United Kingdom
AS16276OVH SAS
97--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12C31CCA5FCD2A4313676B6B016FFF20CAA7A548BE5049804B45D0C593FF0E998E53F88

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hcdJ3Rp4MghCcjhC8hAML1SUh50P0q2yYDkMxCLXspx4AsTc5GFCS44MWHE4CGhW:S/RpbOC0CCVWSPxCLcpoCS4bOhW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1667:AEAAQAAAAAABAAAgAAEBAgAAAAFBAAACQAAAAAADAARAEAAAAUAIAAAAAAAAAAAAAAAAQAAAAAAAEoAAAAQAigAgQAACAAQA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0119191919191901
Perceptual Hash:88dd337329dc2633
Difference Hash:153131b331313131
Wavelet Hash:0119191919191919
Color Hash:#862d3e

Other Hashes

Crop Resistant:153131b331313111

Scan History

Scan history not available

Unable to load historical scan data