Security Scan Report: blue-leaf-5cd6.hgthpisoa-0f6.workers.dev

Redirected to:
https://blue-leaf-5cd6.hgthpisoa-0f6.workers.dev/facebook.com-10272755...
Site favicon
Submitted: Sep 29, 2026, 12:45:15 PMCompleted: Sep 29, 2026, 12:45:58 PMpubliccompleted

This website contacted 8 IPs in 2 countries across 4 domains to perform 23 HTTP transactions. The main domain is blue-leaf-5cd6.hgthpisoa-0f6.workers.dev and was registered 15 years ago.

Submitted URL: https://blue-leaf-5cd6.hgthpisoa-0f6.workers.dev/meta.help

Effective URL:

https://blue-leaf-5cd6.hgthpisoa-0f6.workers.dev/facebook.com-10272755...
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Fake Meta/Facebook 'Page Appeal' phishing page on an unrelated workers.dev subdomain, harvesting password, email, phone and two-factor codes under a false account-restriction warning.

Risk Factors (5)
Impersonation of Meta/Facebook brand on a domain that is not Meta's
Credential collection (password, email, phone, 2FA code) via an appeal form
Fear/urgency social engineering ('temporarily restricted', 'enforcement actions pending')
Hosted on free shared workers.dev subdomain with unknown creation date
Unranked domain with URL paths crafted to look like Meta/Facebook properties
Domain age information unavailable

Details

Page Title

Meta for Business - Page Appeal

Scan Type

public

Domain Name Analysis

The domain name 'blue-leaf-5cd6.hgthpisoa-0f6.workers.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'blue-leaf-5cd6.hgthpisoa-0f6'. Count 7 characters in 'workers' with 2 vowels and five consonants. It segments into one word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://blue-leaf-5cd6.hgthpisoa-0f6.workers.dev/meta.help

Page Load Overview

2.82s
Total Load Time
1.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:10,949 chars
Detector Agreement:75%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9104.21.34.161Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.95Google · CDNUnited States
AS15169Google LLC
2195.181.175.41Datacamp · CDNFrankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
2172.67.75.166Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.163.16Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
237.19.194.81Datacamp · CDNFrankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
2195.181.170.19Datacamp · CDNFrankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
2212.102.56.179Datacamp · CDNFrankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
238--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12444E86633F9217A0147A0BA5E2F860B7735D487660A58083E5C07D80F5EC76E6B7BF8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:eUq1d0IC7HQBEUSFKyngj8ukBfTAlv4XK/IT6f:3q1d0UTSFKynO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:273653:4AggIE7iEIQA4JEwViRMgQDAADKACkAIEKIDQYhWSNoBCMSIIPFlAjd+I0CABvjgCAJjSGUomcGRAECAxEECgaAKZaxJCAYB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c383f3e3e3f3f7e3
Perceptual Hash:e5981a4c6393e5d3
Difference Hash:2e3e260e0606064f
Wavelet Hash:838383e3e3c3e3e1
Color Hash:#405bbf

Scan History

Scan history not available

Unable to load historical scan data