Security Scan Report: 1-erw.pages.dev

Submitted: Jan 3, 2026, 8:22:23 AMCompleted: Jan 3, 2026, 8:24:26 AMpubliccompleted
Loading additional data...

Summary

This website contacted 23 IPs in 4 countries across 15 domains to perform 69 HTTP transactions. The main domain is 1-erw.pages.dev and was registered NaN years ago.

Submitted URL: https://1-erw.pages.dev/nl

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Site impersonates Ookla Speedtest on a malicious, unranked domain – high‑risk phishing, do not use.

Risk Factors
Malicious Indicators of Compromise match (pages.dev)
Brand impersonation of Ookla Speedtest on an unrelated domain
Unranked/low‑reputation domain
Use of pages.dev subdomain, commonly associated with malicious sites
Non‑functional content (server list fetch error)
Domain age information unavailable

Details

Page Title

Speedtest door Ookla - De wereldwijde breedbandsnelheidstest

Scan Type

public

Language

🇳🇱

Dutch

(80% confidence)

Category

technology software

(59%)

Domain Information

The domain name '1-erw.pages.dev' uses the developer-focused generic top-level domain (.dev) with subdomain '1-erw'. Its registrable label 'pages' stretches across 5 characters containing 2 vowels alongside three consonants. Word splitting yields one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://1-erw.pages.dev/nl

Page Load Overview

58.20s
Total Load Time
57
HTTP Requests
20
Domains
2.6 MB
Total Size

Language Analysis

Primary Language

🇳🇱Dutch
Code: nl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:nl
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:nl
Text Length:3,716 chars
Detector Agreement:60%

Website Classification

Primary Category

technology software59% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
59%
download file sharing
57%
documentation technical
44%
government public service
34%
corporate
25%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
133.212.181.164Ashburn, Virginia, United States
AS14618AMAZON-AES
2178.250.1.12France
AS44788Criteo Technology SAS
244.219.128.126France
2162.19.138.120United States
2104.126.37.43Togo
223.56.202.65Frankfurt am Main, Hesse, Germany
AS16625AKAMAI-AS
264.233.167.84United States
AS15169GOOGLE
234.120.133.55Kansas City, Missouri, United States
AS396982GOOGLE-CLOUD-PLATFORM
213.226.244.23Unknown
2146.75.122.219Frankfurt am Main, Hesse, Germany
AS54113FASTLY
5723--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E6F309F522BC535D908B875DEF36B608630FE0B7B5A689D5BB5D8F644B839E4E803840

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:EsM+HuH4yvZs0xE6J/CgbcVKzoKeMXKLnpI6dDcPXE+ymj6aslNzlbsjq0Aok3sd:U7bZbagbcVMaWUZD+3UbwnZLV

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:168685:gQiZCoQIBpCIgRjEFJAIBAzAAEC5EQQyqCsLAoBI6oJsyCDtMuWHqQhAmgAXoA4WEIYuCAQWgiBRGBULERU0UQMwi6ghBYgY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffff0100
Perceptual Hash:aad52af133c58a55
Difference Hash:9971616111010101
Wavelet Hash:7f3b3b3b073f0100
Color Hash:#931f3a

Other Hashes

Crop Resistant:9971616111010101

Scan History

Scan history not available

Unable to load historical scan data