Security Scan Report: zd1.newhill.workers.dev

Bot Protection Detected

This website is protected by CAPTCHA or anti-bot measures that prevented automated scanning.

Submitted: Dec 6, 2025, 12:02:44 PMCompleted: Dec 6, 2025, 12:04:35 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is zd1.newhill.workers.dev.

Submitted URL: https://zd1.newhill.workers.dev/

Effective URL: chrome://new-tab-page/Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Impersonates Google on a new, unranked domain – likely a phishing page.

Risk Factors
Brand impersonation of Google on an unranked, likely new domain
Unranked domain with no established reputation
Potentially newly registered domain
CAPTCHA/anti‑bot protection suggesting suspicious activity
Domain age information unavailable

Details

Page Title

New Tab

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'zd1.newhill.workers.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'zd1.newhill'. Its registrable label 'workers' stretches across 7 characters containing two vowels alongside five consonants. Segmentation suggests 1 word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zd1.newhill.workers.dev/

Page Load Overview

0.18s
Total Load Time
2
HTTP Requests
2
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:7 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1172.64.154.96United States
AS13335CLOUDFLARENET
1172.67.151.20United States
AS13335CLOUDFLARENET
0104.18.33.160United States
AS13335CLOUDFLARENET
02606:4700:3032::ac43:9714United States
AS13335CLOUDFLARENET
02606:4700:3032::6815:2070United States
AS13335CLOUDFLARENET
0104.21.32.112United States
AS13335CLOUDFLARENET
26--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15D736AF5D6F96394158FC3D5EB661895AF3E10FB264981A4722C9BF0AF11898CF87C80

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:7IkPaMxf/N6cw15UxDTti0xhfK6DV/JPsEnOJwNtPDsTSq:ok2AZzxLDV/JJw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:76890:RIYMOK2AEEDgQDBaJiMiEAMimGHhtRCDBAgAAE4cEzvCjQCBWDAKswRAgBgOUAJJRKELoJnGwFlciSBaAyEAyAEgqEzGRaCH

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e6c7c3e7fffffffe
Perceptual Hash:f7225588dd88dd89
Difference Hash:080c1e0800000000
Wavelet Hash:3e2703270f0f0d0c
Color Hash:#64d22d

Other Hashes

Crop Resistant:080c1e0800000000

Scan History

Scan history not available

Unable to load historical scan data