Security Scan Report: t111-3hh.pages.dev

Site favicon
Submitted: Dec 29, 2025, 7:43:40 PMCompleted: Dec 29, 2025, 7:44:56 PMpubliccompleted
Loading additional data...

Summary

This website contacted 21 IPs in 4 countries across 15 domains to perform 69 HTTP transactions. The main domain is t111-3hh.pages.dev and was registered NaN years ago.

Submitted URL: https://t111-3hh.pages.dev/de

AI Security Verdict

High Risk

Confidence: 95%

9
Risk Score

High‑risk phishing site impersonating Ookla Speedtest; do not use.

Risk Factors
Primary domain matches a known malicious Indicator of Compromise
Brand impersonation of a well‑known service (Ookla Speedtest)
Unranked/low‑reputation domain
Multiple redirects may obscure true destination
Domain age information unavailable

Details

Page Title

Speedtest von Ookla - Der umfassende Breitband-Geschwindigkeitstest

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

technology software

(52%)

Domain Information

Domain 't111-3hh.pages.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 't111-3hh'. Count 5 characters in 'pages' containing 2 vowels alongside three consonants. Word splitting yields one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://t111-3hh.pages.dev/de

Page Load Overview

2.24s
Total Load Time
48
HTTP Requests
17
Domains
2.1 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:2,397 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software52% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
52%
government public service
27%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
813.226.244.23Sweden
2162.19.138.118Frankfurt am Main, Hesse, Germany
AS16276OVH SAS
223.207.210.140United States
252.201.222.1France
2172.66.47.198United States
AS13335CLOUDFLARENET
223.56.202.65Unknown
2178.250.1.12Unknown
218.245.31.92Unknown
2142.251.208.10Unknown
2172.66.44.58United States
AS13335CLOUDFLARENET
4821--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FD1408F162B8536D908B879DAF36A618770FE0B7F99649C5B79D8B644B83CE0EC03404

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:p/1Pfo54yvgs0xE6J/CgbcVKzoKeMXKLnpI6dDcPXE+ymj6aslNzlbsjq0Aok39Z:/ObgbagbcVMaWUZD+3UbwnZjKs5zyt9F

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:195793:EoFmAXSCwhCyoUEFZgArCBgI0BYaB51Y0lGNA4GEAgBCmg6FnBAE7jQBHoU0ATDQWJDoCCEIZCXAzAJJBAQhNEGCAMwAFVIQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:6fb9ddfdfdfd1101
Perceptual Hash:aad532f30bd522d1
Difference Hash:9931353131a521a1
Wavelet Hash:7f39393939190101
Color Hash:#539aac

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data