Security Scan Report: pub-6d805fed521749fbba49267aba5ebb7d.r2.dev

Submitted: Sep 28, 2026, 8:53:44 PMCompleted: Sep 28, 2026, 8:54:17 PMpubliccompleted

This website contacted 6 IPs in 1 country across 4 domains to perform 6 HTTP transactions. The main domain is pub-6d805fed521749fbba49267aba5ebb7d.r2.dev and was registered 17 years ago.

Submitted URL: https://pub-6d805fed521749fbba49267aba5ebb7d.r2.dev/baracuda-microsoft-online.office365.com.html

AI Security Verdict

High Risk

Confidence: 76%

8
Risk Score

Brand-impersonating 'office365.com' HTML file hosted on a Cloudflare R2 public bucket, with no legitimate content and a scripted fetch to an unranked .ru domain. No form captured, but impersonation plus anonymous hosting warrants HIGH_RISK.

Risk Factors (4)
Impersonation of Microsoft/Office 365 branding via filename on a non-Microsoft cloud-storage host
Suspicious cross-origin fetch to an unranked, unrelated .ru domain
Hosted on a free, anonymous-publish Cloudflare R2 bucket with no attribution
Zero page content/OCR rendered, indicating script-driven behavior typical of phishing kits
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Domain 'pub-6d805fed521749fbba49267aba5ebb7d.r2.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-6d805fed521749fbba49267aba5ebb7d'. Count 2 characters in 'r2' split between 0 vowels and one consonant; bonus characters include one digit. Splitting it apart reveals two words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-6d805fed521749fbba49267aba5ebb7d.r2.dev/baracuda-microsoft-online.office365.com.html

Page Load Overview

0.62s
Total Load Time
75 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

0
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
66--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T126C1B5606678103D9243D352A6F6DF9E097FD24F86039CBA73AC15C78BC989885E78D2

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:L+k7cVyjXp/Y6gMyxgtUDvSZrdZcd2UklivTHHW2zu3FR:Ltw4j9pExwUDvgrdC49livTWf3FR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6040:WSIAKSGJwBQCbICwBAQUBEAhCCAAgJckELGKyEIAxUDLIwZMkKGIAUUQAQCMAAUIAiBCYgICAoEEAEBCMgkpJJgCIQkIKAgE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e62699cc663399cc
Difference Hash:0008000c0c000800
Wavelet Hash:30303820070f3f3f
Color Hash:#ac7a53

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data