Security Scan Report: pub-f46924b64d9641f6a0cbcfdc1cd89d24.r2.dev

Redirected to:
https://bafybeibsqrtek2xohai4wovizdy53y4zwfvdpelrmeq7apktcqcoeecztu.ip...
Submitted: Oct 3, 2026, 10:54:45 PMCompleted: Oct 3, 2026, 10:55:23 PMpubliccompleted

This website contacted 4 IPs in 1 country across 3 domains to perform 5 HTTP transactions. The main domain is bafybeibsqrtek2xohai4wovizdy53y4zwfvdpelrmeq7apktcqcoeecztu.ipfs.inbrowser.link and was registered 9 years ago.

Submitted URL: http://pub-f46924b64d9641f6a0cbcfdc1cd89d24.r2.dev/oautth.html

Effective URL:

https://bafybeibsqrtek2xohai4wovizdy53y4zwfvdpelrmeq7apktcqcoeecztu.ip...
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake 'Outlook Web App' login landing hosted on a public R2 bucket redirected to IPFS, flagged by a HIGH IDS OWA-phishing alert. No form captured, but brand impersonation and phishing infrastructure warrant avoiding it.

Risk Factors (5)
Impersonation of Microsoft Outlook Web App on a non-Microsoft, unranked domain
Network IDS HIGH phishing alert for an OWA mail phishing landing
Hosted on a public Cloudflare R2 bucket redirected to an IPFS gateway (throwaway infrastructure)
Misspelled 'oautth.html' filename consistent with credential-harvesting kits
Bot-protection/challenge mismatch between scanner and real-client content
Domain age information unavailable

Details

Page Title

Outlook Web App

Scan Type

public

Domain Name Analysis

You're looking at domain 'pub-f46924b64d9641f6a0cbcfdc1cd89d24.r2.dev' on the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-f46924b64d9641f6a0cbcfdc1cd89d24'. The core label 'r2' covers 2 characters holding zero vowels versus one consonant, plus one digit. Tokenizing the label suggests 2 words: r, 2. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://pub-f46924b64d9641f6a0cbcfdc1cd89d24.r2.dev/oautth.html

Page Load Overview

1.27s
Total Load Time
68 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Text Length:15 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1209.94.90.3United States
AS40680Protocol Labs
1209.94.90.2United States
AS40680Protocol Labs
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
54--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EC631E8567C1B882028B5B72731FB6E6F52E4DE871C80C8EF500B890F5EEA11FAE4575

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:HQASuEq79T9LonWZK1TdL++AkATQSPybwFLAIVToaXYZJ4O:IY98WZsZy+sX1ZT3MR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:68506:TOiGgERyAggUnZEAM0AvgkKQB4ittMm95usOHpKCJACkpAJUBQ6AREA0SBQDBR6USEekCKQAIS4RLDiEosQIOjojEUSAXASB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3fffffffffffff
Perceptual Hash:8303030303f7fefe
Difference Hash:c0c0000000000000
Wavelet Hash:3030f0f0f0f0f0f0
Color Hash:#2dd298

Other Hashes

Crop Resistant:c0c0000000000000

Scan History

Scan history not available

Unable to load historical scan data