Security Scan Report: pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev

Submitted: Sep 27, 2026, 8:52:51 PMCompleted: Sep 27, 2026, 8:53:27 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake Outlook login on an anonymous Cloudflare R2 bucket, harvesting email/password, with a CRITICAL heap-spray IDS alert and obfuscated scripts. Textbook credential phishing — do not enter credentials.

Risk Factors (5)
Impersonation of Microsoft Outlook branding on a cloud-storage bucket unrelated to Microsoft
Login/credential harvesting form (2 password + multiple email fields) on shared cloud storage
CRITICAL network IDS heap-spray/shellcode alert
Hex-obfuscated script tag / obfuscated JavaScript (anti-analysis)
Unranked hosting subdomain whose apex age is the platform's, not this page's — effective page age unknown
Domain age information unavailable

Details

Page Title

Credentials

Scan Type

public

Domain Name Analysis

The domain name 'pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev' uses the developer-focused generic top-level domain (.dev) with subdomain 'pub-d44e201c1f3e400586cb81b0f2d48f61'. The second-level label 'r2' is 2 characters long split between zero vowels and one consonant; bonus characters include one digit. Word splitting yields 2 words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-d44e201c1f3e400586cb81b0f2d48f61.r2.dev/owasecure.htm

Page Load Overview

1.10s
Total Load Time
473 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:691 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical81% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
81%
technology software
80%
news media journalism
80%
documentation technical
79%
government public service
78%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.110.101Google · CDNUnited States
AS15169Google LLC
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.13.95Google · CDNUnited States
AS15169Google LLC
1142.251.110.94Google · CDNUnited States
AS15169Google LLC
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2215--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E714987D7611CC4EAD33A9BFFCA82FD090149E4BECCDABC41459545A6FE14AA31082DB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:zDPOLijROgMGPgzv6gVbqcijlNEkF5F4nFuJw+STcQROvdg7k:Jjz9JzZVg7k

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:208764:EgTAggiiDRDCEGA4gQiJBBHATKFAgKALOAnFiAoeYg7AMiLQOIEUEKwoOkSyyEAywCoBgAVKbCEAgEUYRBkhhiPQIqqEEoG2

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd8d8d0d0d0
Wavelet Hash:3f273f3f3f300000
Color Hash:#663a78

Scan History

Scan history not available

Unable to load historical scan data