Security Scan Report: shared-prod.gtag-cf.com

Submitted: Nov 27, 2025, 12:05:14 AMCompleted: Nov 27, 2025, 12:08:04 AMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 2 countries across 2 domains to perform 5 HTTP transactions. The main domain is shared-prod.gtag-cf.com and was registered NaN years ago.

Submitted URL: https://shared-prod.gtag-cf.com/

The Cisco Umbrella rank of the primary domain is #919,168 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Site mimics Microsoft Azure on a low‑rank domain; likely phishing.

Risk Factors
Brand impersonation on a low‑ranking domain
Low Cisco Umbrella ranking for a site claiming Microsoft branding
Domain age information unavailable

Details

Page Title

Your Azure Function App is up and running.

Scan Type

public

Language

🇺🇸

English

(53% confidence)

Category

technology software

(73%)

Domain Information

The domain name 'shared-prod.gtag-cf.com' uses the commercial generic top-level domain (.com), featuring subdomain 'shared-prod'. The core label 'gtag-cf' covers 7 characters split between one vowel and five consonants, plus one hyphen. It segments into three words: g, tag, cf. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://shared-prod.gtag-cf.com/

Page Load Overview

0.80s
Total Load Time
5
HTTP Requests
2
Domains
150 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:53%
Script Type:Latin
Text Length:194 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software73% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
73%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3184.24.77.9Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2104.26.4.78United States
AS13335CLOUDFLARENET
0184.24.77.36Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
0172.67.68.253United States
AS13335CLOUDFLARENET
02606:4700:20::681a:44eUnited States
AS13335CLOUDFLARENET
02606:4700:20::ac43:44fdUnited States
AS13335CLOUDFLARENET
02a02:26f0:7100::213:c650Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
02606:4700:20::681a:54eUnited States
AS13335CLOUDFLARENET
0104.26.5.78United States
AS13335CLOUDFLARENET
02a02:26f0:7100::1720:ee28Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
510--

Detected Technologies1

JQueryv3.6.0
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T171F3D0BA351BFCAFDF3559C792146C216C0E44A75305C689BBAC023C8F96324CF5A7A8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:PY3KIrxJZ6XQ6OLR+NkipGG2zTGjUG6dW1N:x676XQ6E2jCTGQk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:163867:jiAQOEwRBwJAlAYIWSmAUABAhCw4AEWMYDQAGS2ESQO0WBSTSIFIyygALmJgRGlSMQJRwE0oDBzBpHiCQg0FiCAJsjKRWuUA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:070707060203017f
Perceptual Hash:b4b4ea694a4ab55a
Difference Hash:8d8cccac8e96c9a7
Wavelet Hash:47070f07434363ff
Color Hash:#622d86

Scan History

Scan history not available

Unable to load historical scan data