Security Scan Report: flao.keki.workers.dev

Submitted: Sep 22, 2026, 12:45:17 PMCompleted: Sep 22, 2026, 12:45:36 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

Fake 'Visa Secure' page on a workers.dev subdomain asks users to enter credit-card details in exchange for a $1 reward — Visa brand impersonation card-phishing, flagged as phishing by threat intel.

Risk Factors (5)
Impersonation of the Visa brand on a non-Visa domain
Free instant-subdomain hosting platform (.workers.dev) with unknown, potentially minutes-old creation date
Financial reward offered in exchange for credit-card verification (phishing lure)
Threat-intelligence phishing report on the primary domain
Obfuscated/heuristic JavaScript content detected by network IDS hunting rules
Domain age information unavailable

Details

Page Title

Visa | توثيق البطاقة الائتمانية

Scan Type

public

Domain Name Analysis

The domain 'flao.keki.workers.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'flao.keki'. The second-level label 'workers' is 7 characters long with two vowels and 5 consonants. Word splitting yields one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://flao.keki.workers.dev/visa?chatId=1869190386

Page Load Overview

0.60s
Total Load Time
503 KB
Total Size

Language Analysis

Primary Language

🇸🇦Arabic
Code: ar
Confidence:80%
Script:Arabic
Direction:rtl

Detection Details

HTML Lang Attribute:ar
Text Length:707 chars
Detector Agreement:100%

Website Classification

Primary Category

gambling betting82% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

gambling betting
82%
finance banking
69%
adult content
54%
government public service
40%
healthcare medical
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.67.145.67Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
274.125.29.95Google · CDNUnited States
AS15169Google LLC
2104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.217.208.95Google · CDNUnited States
AS15169Google LLC
2104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.250.154.94Google · CDNUnited States
AS15169Google LLC
146--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T103B2F70A3563C15D3613E6AE7F721786E0A1870BC546CB76BC4CDA54CF86943EA5E338

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:M0nUL6AnwyEEu30UCtOAW2aiKkpxBwXRLS:M0nULFwHEu30UCtZW2aiKkpxBwXRW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24886:6AXCUAhAoSU4lhJJDqAoEcskoABYJZvqHXCgQAyesACUFKF2MAdjAQqIBDIAJCgskmogYQSIR8AbBKAAQMILAQwjkBxBQSLA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:010101193d01050d
Perceptual Hash:8a5537978c24369f
Difference Hash:d5e9d5b1b155ddfd
Wavelet Hash:0303071f3f0f1f1f
Color Hash:#78763a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data