Security Scan Report: dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev

Submitted: Sep 14, 2026, 2:50:03 PMCompleted: Sep 14, 2026, 2:50:24 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed Spotify phishing kit on an edgeone.dev subdomain: fake login plus card/CVV capture, DevTools blocking, and JavaScript credential exfiltration to an external Telegram endpoint.

Risk Factors (5)
Impersonation of Spotify brand on a non-official, unranked hosting-platform subdomain
Password field plus full credit-card field set (card number, expiry, CVV, cardholder name) collected
Credential exfiltration over the network to an external Telegram relay (workers.dev)
Anti-analysis: DevTools and right-click blocking combined with data harvesting
Domain not in Cisco Umbrella top 1M; subdomain creation date unknown (shared hosting tenant)
Domain age information unavailable

Details

Page Title

spotify

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev' is registered, featuring subdomain 'dead-coffee-vczxixdn-dpwj3cuq93cf'. The registrable portion 'edgeone' spans 7 characters containing 4 vowels alongside 3 consonants. Segmentation suggests two words: edge, one. The median word length lands at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dead-coffee-vczxixdn-dpwj3cuq93cf.edgeone.dev/

Page Load Overview

1.93s
Total Load Time
267 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,730 chars
Detector Agreement:67%

Website Classification

Primary Category

entertainment media33% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.43.142.5United Kingdom
AS16276OVH SAS
143.174.246.29Singapore
143.174.247.29Singapore
145.43.142.3United Kingdom
AS16276OVH SAS
145.43.142.2United Kingdom
AS16276OVH SAS
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
97--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12C31CCA5FCD2A4313676B6B016FFF20CAA7A548BE5049804B45D0C593FF0E998E53F88

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hcdJ3Rp4MghCcjhC8hAML1SUh50P0q2yYDkMxCLXspx4AsTc5GFCS44MWHE4CGhW:S/RpbOC0CCVWSPxCLcpoCS4bOhW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1667:AEAAQAAAAAABAAAgAAEBAgAAAAFBAAACQAAAAAADAARAEAAAAUAIAAAAAAAAAAAAAAAAQAAAAAAAEoAAAAQAigAgQAACAAQA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0119191919191901
Perceptual Hash:88dd337329dc2633
Difference Hash:153131b331313131
Wavelet Hash:0119191919191919
Color Hash:#3c862d

Other Hashes

Crop Resistant:153131b331313111

Scan History

Scan history not available

Unable to load historical scan data