Security Scan Report: pub-c443207085e4408eae3253a53de7517c.r2.dev

Submitted: Oct 7, 2026, 12:45:16 AMCompleted: Oct 7, 2026, 12:46:01 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page impersonating BellMTS/MTS Mail on a Cloudflare R2 bucket, harvesting login credentials and full payment-card details (CVV, card number). Do not enter any information.

Risk Factors (5)
Brand impersonation of BellMTS on an unrelated cloud-storage subdomain
Credential harvesting: login/password form collecting mymts.net email addresses
Payment-card harvesting: Card Number, Expiry, CVV, Name on card, Address, Zipcode fields
Cloudflare R2 public bucket hosting typical of throwaway phishing kits
Domain unranked in Cisco Umbrella top 1M while claiming a major brand's login
Domain age information unavailable

Details

Page Title

MTS Mail | Login

Scan Type

public

Domain Name Analysis

Domain 'pub-c443207085e4408eae3253a53de7517c.r2.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'pub-c443207085e4408eae3253a53de7517c'. Count 2 characters in 'r2' holding zero vowels versus one consonant, notching 1 digit. Segmentation suggests two words: r, 2. Median word length comes out to 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-c443207085e4408eae3253a53de7517c.r2.dev/gfds.html

Page Load Overview

2.25s
Total Load Time
151 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:615 chars
Detector Agreement:100%

Website Classification

Primary Category

social_media50% confidence
Type: webapp
Method: structural

All Detected Categories

social_media
50%
e-commerce
40%

Detected Features

Login Form
Payment

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3104.18.54.45Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2140.238.130.32Oracle · CLOUDToronto, Ontario, Canada
AS31898Oracle Corporation
2129.159.124.34Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
2104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.21.25.148Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
115--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16862A71A78FB08710A93D099B6EB9D093C74D513D909CC8879AC8B881FC6ED5C8A739C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ng0gvxY/xuEkgo9JEmYgTekE/g9VB2pVtNpv0htBpYsUeStxV98z4FQlh6Ac3+AN:ng0g5YQIzlNkdLorKm4z4FQDiiliei1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15257:BEGUSBSSCJVScgIYIIo4fEKiiiCIEMjaiKkgTAikEhEQwkBICQDMHgAJiHyhJRAYOBAgiQDCZAjCaJA4KTkrJPwkuEEUcHKE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffefe7e7e7ffff
Perceptual Hash:b399cc6666999926
Difference Hash:0000080c0c0c0000
Wavelet Hash:3c3c2424e4e4fcfc
Color Hash:#785b3a

Other Hashes

Crop Resistant:0000080c0c0c0000

Scan History

Scan history not available

Unable to load historical scan data