Security Scan Report: drf-752.pages.dev

Site favicon
Submitted: Jan 3, 2026, 8:58:40 AMCompleted: Jan 3, 2026, 9:00:07 AMpubliccompleted
Loading additional data...

Summary

This website contacted 13 IPs in 1 country across 9 domains to perform 129 HTTP transactions. The main domain is drf-752.pages.dev and was registered NaN years ago.

Submitted URL: https://drf-752.pages.dev/

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High risk phishing site impersonating WTO; do not trust or provide any credentials.

Risk Factors
Malicious primary domain Indicator of Compromise (pages.dev)
Brand impersonation of WTO on a non‑official, unranked domain
Use of a suspicious subdomain (drf-752.pages.dev) under a malicious parent domain
Domain age information unavailable

Details

Page Title

Visa, ein zuverlässiger Partner für digitale Zahlungen | Visa

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain 'drf-752.pages.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'drf-752'. Count 5 characters in 'pages' holding two vowels versus 3 consonants. Splitting it apart reveals one word: pages. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://drf-752.pages.dev/

Page Load Overview

12.23s
Total Load Time
80
HTTP Requests
6
Domains
1.9 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,856 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: spa
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
813.33.187.60United States
6104.18.2.150United States
6104.18.4.226United States
6104.18.3.150United States
6104.18.14.129United StatesUnknown
6142.250.185.142United StatesUnknown
6104.18.66.57United StatesUnknown
6188.114.97.3United States
AS13335CLOUDFLARENET
6142.251.140.174United StatesUnknown
634.107.253.133United StatesUnknown
8013--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E814A772B0CA241E4223A0E591B5BB08F8F1910BC28528D4FABD47752FC5F72BD5766E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:J9sNhOw5mUvtx59VRJFAuRnl/JXF/cqfvN7VXtT1A2xP1nZfFX42LxM6hrB/h06M:IEw5mU9WxObJrMGTWmGw2fA+7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:205195:EqLiYCAhKJpCAwDLEaGagIwEEK+CApQGAkC5QO1xw+CMASZUYINCFBcKAoAEPjtOUghGPJFBFADExekBYlB0ngYgmAtDcIQZ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0020ffffffffffff
Perceptual Hash:ea07476a1b2b19f8
Difference Hash:61653211b1958181
Wavelet Hash:0000fff9ddc5c1f8
Color Hash:#782d86

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data