Security Scan Report: pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev

Site favicon
Submitted: Sep 26, 2026, 11:50:40 PMCompleted: Sep 26, 2026, 11:51:58 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing page impersonating NetEase Enterprise Email (网易企业邮箱) login, hosted on a random Cloudflare R2 bucket, harvesting email/password credentials. Do not enter credentials.

Risk Factors (5)
Brand impersonation of NetEase (网易) enterprise email on a non-official domain
Login/password form harvesting credentials on a Cloudflare R2 public bucket
Cloud-storage hosting with credential collection (shared, disposable namespace) — phishing-kit pattern
Unranked domain not in Cisco Umbrella top 1M
Obfuscated/decoding inline JavaScript functions
Domain age information unavailable

Details

Page Title

网易企业邮箱 - 登录入口

Scan Type

public

Domain Name Analysis

Domain 'pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-d32e1723091e4c74b19f3caea6a4ed0a'. Count 2 characters in 'r2' split between 0 vowels and one consonant; bonus characters include 1 digit. Segmentation suggests two words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-d32e1723091e4c74b19f3caea6a4ed0a.r2.dev/qiye-revised/index.html

Page Load Overview

0.54s
Total Load Time
227 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:13 chars
Detector Agreement:0%

Website Classification

Primary Category

healthcare medical65% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
65%
government public service
62%
real estate property
59%
finance banking
53%
news media journalism
52%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1103.126.92.250Hong Kong
AS137263NETEASE HONG KONG LIMITED
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1103.126.92.249Hong Kong
AS137263NETEASE HONG KONG LIMITED
65--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17D61B5957CA963A53AB301F420F7969C155DC1027708C840F47CB5C9AF95FC9B533568

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:qjqeDDhfHHBfKqBRdQHVK1CUqo+yWwdxD1I:4DVntz0VK1CUqoFm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3356:AgAkMAAMDMEQNAAxMIoEAhAAAICQQIAACBEIEQCEAAAogIQAgAQEQKCAFQCgABABAAARAgCUBoYAQCAIAAgDIUgAYnAUCQQg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:18183838180000ff
Perceptual Hash:c959b636e067a626
Difference Hash:b2f2f2f2b20d1080
Wavelet Hash:1c7c7c7cfc0000ff
Color Hash:#71ac53

Scan History

Scan history not available

Unable to load historical scan data