Security Scan Report: pub-3658de85013d43a281c3176278dc8624.r2.dev

Site favicon
Submitted: Nov 3, 2025, 12:15:54 AMCompleted: Nov 3, 2025, 12:17:07 AMpubliccompleted
Loading additional data...

Summary

This website contacted 75 IPs in 5 countries across 24 domains to perform 67 HTTP transactions. The main domain is pub-3658de85013d43a281c3176278dc8624.r2.dev.

Submitted URL: https://pub-3658de85013d43a281c3176278dc8624.r2.dev/index.html

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating The Courier Guy to collect payment; do not provide any data.

Risk Factors
Brand impersonation on an untrusted domain
Payment fields on a suspicious, non‑official domain
Urgent payment demand to pressure the user
Hosting on a cloud storage domain (r2.dev) rather than a legitimate corporate host
Domain lacks reputation (unranked) and likely very new
Domain age information unavailable

Details

Page Title

The Courier Guy

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(56%)

Domain Information

Within the developer-focused generic top-level domain (.dev), 'pub-3658de85013d43a281c3176278dc8624.r2.dev' is registered; it also runs on subdomain 'pub-3658de85013d43a281c3176278dc8624'. Count 2 characters in 'r2' with zero vowels and one consonant, along with 1 digit. Tokenizing the label suggests 2 words: r, 2. The median word length lands at 1 character. 'r' most often appears in Chinese (Zhuyin). You will also see it in Sinhala and Chinese (Simplified) contexts. Net impression: Chinese (Zhuyin) phrase with character flair.

Screenshot

Security scan screenshot of https://pub-3658de85013d43a281c3176278dc8624.r2.dev/index.html

Page Load Overview

16.04s
Total Load Time
67
HTTP Requests
24
Domains
2.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:644 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking56% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
56%
government public service
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6718.66.102.11United States
AS16509AMAZON-02
052.242.103.142Boydton, Virginia, United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
020.250.198.32Zurich, Zurich, Switzerland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
034.143.72.2United States
AS396982GOOGLE-CLOUD-PLATFORM
0142.250.181.234United States
AS15169GOOGLE
0157.240.0.35Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
0150.171.22.12United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
0142.250.184.227United States
AS15169GOOGLE
023.53.42.9Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
03.171.214.3United States
AS16509AMAZON-02
6775--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C204D69362A029FA1B338137538E99C8B14C4CD5B913E9E6F5DE94490BC96FE0D13B27

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:r75dHuUmSmemSm8mSmRmSmNXmSm4mSmkmSmewspOO7BWuSpE/TdJlf5fef9fgf+P:7bh7BWCY0wB1swCPXVA

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:175666:yywULKAQhGYEzTjKAIB4MDFIGgcglDJpAEFxSkUDTFDEEwhAyAAq00GqkKMEgaCAHIAJgFhAUIZ7KNwAIRhBGBqahQGBmWRi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:07bbb9c989f3e7ff
Perceptual Hash:bc09863419e7cf3c
Difference Hash:da77639b33274c12
Wavelet Hash:02b381c888f9e3ff
Color Hash:#4048bf

Other Hashes

Crop Resistant:da77639b33274c12

Scan History

Scan history not available

Unable to load historical scan data