Security Scan Report: webmail-dpzfjpa7b5nv.edgeone.dev

Submitted: Sep 30, 2026, 1:51:06 PMCompleted: Sep 30, 2026, 1:51:42 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Fake webmail sign-in on a random edgeone.dev subdomain harvesting email+password, gated by a bogus 'not a robot' check and exfiltrating data via a Telegram bot API call. Confirmed credential phishing — do not enter credentials.

Risk Factors (5)
Credential-harvesting login form (email + password) behind a session-expiry lure
POST to api.telegram.org sendMessage with hardcoded bot token — credential exfiltration endpoint
Fake 'I am not a robot' / browser-check interstitial used as a phishing gate
Mismatched randomized subdomain on free hosting platform presenting as webmail sign-in
IP lookup via ipify and redirect chain indicating kit staging
Domain age information unavailable

Details

Page Title

Webmail Sign-in

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'webmail-dpzfjpa7b5nv.edgeone.dev' is registered; it also runs on subdomain 'webmail-dpzfjpa7b5nv'. The second-level label 'edgeone' is 7 characters long split between 4 vowels and 3 consonants. Splitting it apart reveals two words: edge, one. Median word length is 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://webmail-dpzfjpa7b5nv.edgeone.dev/

Page Load Overview

0.69s
Total Load Time
117 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:248 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain65% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

cryptocurrency blockchain
65%
documentation technical
62%
technology software
57%
healthcare medical
49%
news media journalism
45%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
143.174.246.29Singapore
1151.101.193.229Fastly · CDNUnited States
AS54113Fastly, Inc.
174.125.29.95Google · CDNUnited States
AS15169Google LLC
1142.251.157.119Google · CDNUnited States
AS15169Google LLC
1142.251.14.104Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1104.26.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
143.174.247.29Singapore
1151.101.129.229Fastly · CDNUnited States
AS54113Fastly, Inc.
1151.101.1.229Fastly · CDNUnited States
AS54113Fastly, Inc.
1212--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12E32F762ABBD043D3293D0B931F5A7847E35C107DF41099A78BD2A954FCAE8648777C8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:I7Uq6jfD9jTZLox1JJyo4+KJAM7R0eyiYtmfDrisLiZi4jb2UO4UWOAu:IABX0eyijbriyiZi4jDUWs

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11672:gIBAQUCGCSkwESABQGgRAZIhgKNilBGOBp1QsgwVpImwUG1FIRGEAClCRhAUyJNIACAJyAkC0SABgKIATAMWQCJYAogQIoIk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc3c3ffffffffff
Perceptual Hash:b13164cece9b9931
Difference Hash:0016160000000000
Wavelet Hash:fcc0c0fcf0f0f0f0
Color Hash:#865c2d

Other Hashes

Crop Resistant:0016160000000000

Scan History

Scan history not available

Unable to load historical scan data