Security Scan Report: pub-27aec06579c54f4193bb23484ec6a2f7.r2.dev

Submitted: Sep 28, 2026, 3:53:56 PMCompleted: Sep 28, 2026, 3:54:46 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 62%

5
Risk Score

Unranked Indonesian online-slot gambling page hosted on a public Cloudflare R2 bucket. No forms, credential harvesting, IoC, or malware — gambling promotion itself is the main risk.

Risk Factors (3)
Promotes unlicensed/illegal online gambling targeting Indonesian users
Served from a shared public cloud-storage subdomain with no verifiable operator identity
Unranked, non-brand domain with no published ownership information
Safety Factors (4)
No credential, login, password, or payment form on the page
No Indicators of Compromise matches against the page or its resources
No JavaScript malware (YARA) patterns and no obfuscated/exfiltrating script behavior
Suricata alerts are informational only (R2 bucket DNS/TLS-SNI notices and a generic .cc TLD query), not phishing or malware signatures
Domain age information unavailable

Details

Page Title

Raffi888 Situs Raffi Slot Gacor Malam Ini Banjir Scatter Hitam

Scan Type

public

Domain Name Analysis

The domain name 'pub-27aec06579c54f4193bb23484ec6a2f7.r2.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'pub-27aec06579c54f4193bb23484ec6a2f7'. The registrable portion 'r2' spans 2 characters split between zero vowels and one consonant, notching one digit. Splitting it apart reveals 2 words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-27aec06579c54f4193bb23484ec6a2f7.r2.dev/raffi888.html

Page Load Overview

12.83s
Total Load Time
218 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:id
Text Length:728 chars
Detector Agreement:80%

Website Classification

Primary Category

gambling betting92% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

gambling betting
92%
finance banking
82%
entertainment media
70%
technology software
54%
corporate
35%

Detected Features

Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0192.178.183.132Google · CDNUnited States
AS15169Google LLC
0142.251.20.95Google · CDNUnited States
AS15169Google LLC
0142.251.20.94Google · CDNUnited States
AS15169Google LLC
0195.154.239.25Paris, Île-de-France, France
AS12876Scaleway SAS
045.43.142.3United Kingdom
AS16276OVH SAS
0142.251.13.132Google · CDNUnited States
AS15169Google LLC
0142.251.13.95Google · CDNUnited States
AS15169Google LLC
0142.251.110.94Google · CDNUnited States
AS15169Google LLC
0195.154.239.27Paris, Île-de-France, France
AS12876Scaleway SAS
1011--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13E039817A5D610886103D2755AE6BB3F3D38C40396228D2DBA4D7BACCF86BC5797320E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:7W0A3Xc5F4g5A4WR2vuDn/BlrfFSd2SOd9Y/Be41ysO76xoZ:7Wk5F4g5A4WR2vurZlbFR9Y/Be41ysfW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:37879:oIQIYoiIAAIKIQqlL2CBMRW4QUBSMUnMkhBBgSUxGUAEJBAGIgU8CuU0QiACwmRXgUCAhQqDVRAJEcAQEQUEUGKESlfAQmAK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1818181818181810
Perceptual Hash:9999333366cccc66
Difference Hash:32b2b2b23030b030
Wavelet Hash:3c3c3c3c3c3c3c3c
Color Hash:#b3e06c

Scan History

Scan history not available

Unable to load historical scan data