Security Scan Report: pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev

Redirected to:
https://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm
Submitted: Aug 20, 2026, 1:50:27 AMCompleted: Aug 20, 2026, 1:51:59 AMpubliccompleted

This website contacted 7 IPs in 1 country across 11 domains to perform 21 HTTP transactions. The main domain is pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev and was registered 4 years 1 month ago.

Submitted URL: http://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm

Effective URL:

https://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm
Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Page hosts credential‑stealing forms, is unranked, and triggers Safe Browsing phishing and critical IDS alerts – treat as high‑risk phishing site.

Risk Factors
Credential form on unknown‑age cloud‑storage subdomain
Unranked / low‑reputation domain
Safe Browsing phishing indicator
Critical IDS shellcode alert
Domain age information unavailable

Details

Page Title

Credentials

Scan Type

public

Domain Name Analysis

The domain name 'pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'pub-d44e201c1f3e400586cb81b0f2d48f61'. Count 2 characters in 'r2' containing 0 vowels alongside one consonant, plus one digit. Word splitting yields two words: r, 2. Average segment length settles at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm

Page Load Overview

1.76s
Total Load Time
458 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:691 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical81% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
81%
technology software
80%
news media journalism
80%
documentation technical
79%
government public service
78%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
3151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
3142.251.14.101Google · CDNUnited States
AS15169Google LLC
217--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19CE3067D7611CC4EAD3399BFFCA82FD090149E5BECCDABC40459845A6FE14AA35082DB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:KgZFgVWFEGtig7o2bhf7g7NLl3M4KLuwdmUkCikYkORodfKQxSYd8js9/1m4IDgU:JPOLijROgMGPgzv6gVbqcijl0

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:156321:RU2B0BAFQqSghA+IRiIKAhCIClFBNhFCDOCbCAAQRAEmMw3BZAgEZGSKAATXOYgDUFJB4cNw45jaDqApSoRAyYoWVIlkgAsg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd8d8d0d0d0
Wavelet Hash:3f273f3f3f300000
Color Hash:#799ad2

Scan History

Scan history not available

Unable to load historical scan data