Security Scan Report: pub-c53d218c4f704f2495ca7a15b052e24c.r2.dev

Submitted: Sep 30, 2026, 2:53:23 AMCompleted: Sep 30, 2026, 2:54:41 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

DocuSign-branded credential phishing hosted on a Cloudflare R2 public bucket. Fake login with password field and urgency/error lure to harvest credentials — do not enter any details.

Risk Factors (5)
Brand impersonation of DocuSign on a non-official, cloud-storage-hosted domain
Credential (password) collection form on a public bucket subdomain
Phishing-kit authentication lure with fake error message designed to harvest passwords
Unranked domain with no legitimate business footprint (legitimacy score 10/100)
Hosted on a public R2 bucket where anyone can publish content
Domain age information unavailable

Details

Page Title

DocuSign Login - Enter your password to sign in

Scan Type

public

Domain Name Analysis

Domain 'pub-c53d218c4f704f2495ca7a15b052e24c.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-c53d218c4f704f2495ca7a15b052e24c'. Count 2 characters in 'r2' containing 0 vowels alongside 1 consonant, notching one digit. Word splitting yields two words: r, 2. The median word length lands at one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-c53d218c4f704f2495ca7a15b052e24c.r2.dev/monitor/monitor.html

Page Load Overview

39.94s
Total Load Time
481 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:557 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical39% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
39%
government public service
29%
real estate property
29%
news media journalism
29%
technology software
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0141.193.213.20Cloudflare · CDNUnited States
AS209242Cloudflare London, LLC
0185.111.111.156Frankfurt am Main, Hesse, Germany
AS212238Datacamp Limited
0104.18.43.144Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0187.127.201.248Lithuania
AS47583Hostinger International Limited
0172.64.147.160Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0192.178.183.95Google · CDNUnited States
AS15169Google LLC
0172.64.152.231Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0170.114.78.89Cloudflare · CDNUnited States
AS209242Cloudflare London, LLC
0141.193.213.21Cloudflare · CDNUnited States
AS209242Cloudflare London, LLC
915--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T111448B3249239C2708DED5C7591D6FDA7FA4CDCB46316223B07C818CA791AF22D9A25F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:sajpSYt72uB8zd3nuatHiuZ1aYxs7TA7VmsebIxzFJkzFuOtHXf5n:sa1SYtRc33CMaoQTA7Vmsebr

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:256347:JyNj6AEECAiDlVgUZEjRAysJBNMBvAMTgnAgAARyCJArCAkgSjDhEIACkAs4IpBgQAMuYAUEEmYOZtQDCBBACimxKICQJEfG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffe7efe3ffffef
Perceptual Hash:b38f8c253399c666
Difference Hash:883228484d20308c
Wavelet Hash:7f3c3424243c3cee
Color Hash:#d22d5c

Other Hashes

Crop Resistant:883228484d20308c

Scan History

Scan history not available

Unable to load historical scan data