Security Scan Report: divine-waterfall-66cb.russellgouldaboj15798.workers.dev

Submitted: Sep 18, 2026, 12:45:42 PMCompleted: Sep 18, 2026, 12:46:24 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 88%

3
Risk Score

Cloudflare-flagged phishing page impersonating Meta ('Meta Center') on an anonymous workers.dev subdomain, with a 91% phishing ML classification. Confirmed malicious; do not interact.

Risk Factors (5)
Cloudflare 'Suspected Phishing' warning on the site
Impersonation of Meta brand on a non-Meta domain
Anonymous, unattributable workers.dev subdomain
ML phishing classification at 91% confidence
External IP-geolocation lookup (ipapi.co) on page load
Safety Factors (2)
No credential, password, or payment fields were captured in the served interstitial (Cloudflare's warning page masks the landing content)
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 9 to 3
Domain age information unavailable

Details

Page Title

Meta Center

Scan Type

public

Domain Name Analysis

The domain name 'divine-waterfall-66cb.russellgouldaboj15798.workers.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'divine-waterfall-66cb.russellgouldaboj15798'. Count 7 characters in 'workers' split between two vowels and 5 consonants. Breaking it apart gives 1 word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://divine-waterfall-66cb.russellgouldaboj15798.workers.dev/meta-management-center

Page Load Overview

1.01s
Total Load Time
1021 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:373 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam91% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
91%
technology software
35%
documentation technical
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1172.67.155.83Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1104.21.66.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
55--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EC91325E25F70235A57370792FEB5210353AE0072649CE883FDD93A4AFC66A89173BD8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:Tz9RBh9HTtJvOIsOPJxdy5AZ6O1thXVf4wCNRBi+i7vcqc8nCZBep+59PdmeK:TzthdRJvONMSAZJtJZg3i+XqhC/nvPXK

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4466:AghgEEEJBATADTSAAAEBAAACKUAomEAQgZBgAgBMiRABQEgEYFIUYQgARIAIAIQQwFIgTASugCSQgCCCEAkIgBlgAAECBoEA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff8787ffc7ffffff
Perceptual Hash:b83898c3c3c7ce3c
Difference Hash:203c38000c000000
Wavelet Hash:9c8490c0c0fcfcfc
Color Hash:#6d2d86

Other Hashes

Crop Resistant:203c38000c000000

Scan History

Scan history not available

Unable to load historical scan data