Security Scan Report: pub-f4a21afc244c4ddda2b708bacf755479.r2.dev

Submitted: Sep 27, 2026, 12:50:41 AMCompleted: Sep 27, 2026, 12:52:10 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Credential-phishing page on a Cloudflare R2 bucket: a fake login form captures email + password, with the victim's address pre-seeded in the URL fragment via a document-viewing lure. Do not enter credentials.

Risk Factors (5)
Credential-harvesting login form (1 password field + 1 email field) on unauthenticated cloud-storage hosting
Victim email prefilled via URL fragment (phishing lure / victim-tracking token)
Email domain (x.com) does not match the hosting domain — victim/impersonation mismatch
Generic, brandless 'Login Form' page with no legitimate site identity or ownership signals
Garbled text and misspellings typical of mass-distributed phishing kits
Domain age information unavailable

Details

Page Title

Login Form

Scan Type

public

Domain Name Analysis

The domain name 'pub-f4a21afc244c4ddda2b708bacf755479.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-f4a21afc244c4ddda2b708bacf755479'. Count 2 characters in 'r2' containing zero vowels alongside one consonant; it also includes one digit. Breaking it apart gives two words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-f4a21afc244c4ddda2b708bacf755479.r2.dev/vncr22.html?Yacht366#x@x.com

Page Load Overview

2.20s
Total Load Time
62 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:441 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce shopping70% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

e-commerce shopping
70%
healthcare medical
52%
government public service
44%
documentation technical
44%
technology software
44%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
013.248.169.48Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
034.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
0142.251.155.119Google · CDNUnited States
AS15169Google LLC
0142.250.154.99Google · CDNUnited States
AS15169Google LLC
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.157.119Google · CDNUnited States
AS15169Google LLC
0142.251.20.103Google · CDNUnited States
AS15169Google LLC
0104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
710--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13BD1A8DB7EDB08666A97E1AA3F76D3493430C0071D06C4953D9C21688F51E9BD9AB3C8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:UVLHBGGUx8F1fFv5zmRyqYyJq4PGJpNs9UEjiaiiiHigi4i0ib93Yiti0i2aHp:Uc8F1FT4OpNs9jjiaiiiHigi4i0i+itK

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6245:HACAUAnAGMCAEidBDAlgDgMFI6OABgEkAUCQzASQAFgzSiEoQCzC1A0wAE6EACqARBQABBQCiBkACKkCATAAAyVCkBBCkBwM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:eedea6e6e6e6fefe
Perceptual Hash:f7738c9c89662233
Difference Hash:0a120a0a0a0a120a
Wavelet Hash:02020202e2e2c2c2
Color Hash:#8f1f93

Other Hashes

Crop Resistant:0a120a0a0a0a120a

Scan History

Scan history not available

Unable to load historical scan data