Security Scan Report: elster.pages.dev

Site favicon
Submitted: Oct 4, 2026, 1:55:05 PMCompleted: Oct 4, 2026, 1:55:43 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake ELSTER tax portal on elster.pages.dev that impersonates the German tax authority and submits personal data plus IBAN to the unrelated domain online-finanzministerium.com — a clear phishing scam.

Risk Factors (5)
Impersonation of the ELSTER government tax portal on a non-official pages.dev subdomain
Cross-origin form submission of personal and financial data to online-finanzministerium.com
Collection of IBAN/bank account details, name, address, phone and email
Lure text urging users to 'verify/update their data' — a classic phishing pretext
Unranked domain with unknown subdomain age on shared hosting
Domain age information unavailable

Details

Page Title

ELSTER - Überprüfen Sie jetzt Ihre Daten

Scan Type

public

Domain Name Analysis

Domain 'elster.pages.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'elster'. The registrable portion 'pages' spans 5 characters split between two vowels and three consonants. Splitting it apart reveals one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://elster.pages.dev

Page Load Overview

2.37s
Total Load Time
856 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:4,686 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking75% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
75%
adult content
56%
corporate business
55%
government public service
51%
blog personal website
31%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
14188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
292--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16524C42080F78676127EB485E1E457157B97D33383C9ABFA326C42798BC7CAA4C5B19C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:VnCa6SBq4WhmHMUQTGhYF7cntsq7/msUBKddhzFcV7+esGgEXQEI1BF/WpnKlpk6:VJEmjLKIUuzFcV7+esGg2DQb1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:225512:kV9bLBBpA2bYlh6EpQssAtIAVFGkORBMBIKhM28AAlCFAADCgJxXjABDQYBIHEwGjagjSAAEWiC+tlAg0wYs0G0YiENVUCCk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3a8f0387c3c3c7c3
Perceptual Hash:b55fcbcac0cc6461
Difference Hash:625e16160e0e161e
Wavelet Hash:3a8f8383c3c3c7c3
Color Hash:#2dd29e

Other Hashes

Crop Resistant:625e16160e0e161e

Scan History

Scan history not available

Unable to load historical scan data