Security Scan Report: migrationsite.pages.dev

Submitted: Dec 11, 2025, 5:06:25 AMCompleted: Dec 11, 2025, 5:06:46 AMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 2 countries across 3 domains to perform 36 HTTP transactions. The main domain is migrationsite.pages.dev.

Submitted URL: https://migrationsite.pages.dev/form

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

High risk phishing site collecting sensitive credentials

Risk Factors
New/unregistered domain with no reputation
Unranked domain (not in top 1M) increasing suspicion
Credential harvesting form requesting API keys and tokens
Absence of any legitimate branding or purpose
Domain age information unavailable

Details

Page Title

Geschafft Migration

Scan Type

public

Language

🇺🇸

English

(42% confidence)

Category

government public service

(30%)

Domain Information

Within the developer-focused generic top-level domain (.dev), 'migrationsite.pages.dev' is registered, featuring subdomain 'migrationsite'. Count 5 characters in 'pages' containing two vowels alongside 3 consonants. Segmentation suggests one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://migrationsite.pages.dev/form

Page Load Overview

3.61s
Total Load Time
36
HTTP Requests
3
Domains
157 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:42%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:42%
Script Type:Latin
Text Length:152 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service30% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8172.66.45.10United States
AS13335CLOUDFLARENET
4172.66.46.246United States
AS13335CLOUDFLARENET
4157.240.253.1Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
4142.250.185.174United States
AS15169GOOGLE
42a03:2880:f083:100:face:b00c:0:3Frankfurt am Main, Hesse, Germany
AS32934FACEBOOK
42a00:1450:4001:812::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
42606:4700:310c::ac42:2ef6United States
AS13335CLOUDFLARENET
42606:4700:310c::ac42:2d0aUnited States
AS13335CLOUDFLARENET
368--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13442E826C854A00A612B84C074D4BA4E916EC20FD9E25B6E76FC4E390FD7FD92D63F58

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:rXbcORPgYxTIRPgYxT+Rqj6w16l3Ly+Ef5Qj01/ZQtr3CF6J91SmOL9ptvfqQ3bn:rXbcADiDfj6w15BQqRur3HL1gsNjGiZi

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:13157:ImnENoNY6QCBkQSFIAYhEulCCLggEcGKihQVGgIkUgkcFqCQIgSUKoAEA5GTEyAiEQNA4dSgIGSCiG0GssYIA6sJSkAOQg7W

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9fe7ffffe72400e7
Perceptual Hash:b69c1c369e1c9c36
Difference Hash:2c0c0c120c0c0808
Wavelet Hash:9fe7efefe7000000
Color Hash:#2dd2b1

Other Hashes

Crop Resistant:2c0c0c120c0c0808

Scan History

Scan history not available

Unable to load historical scan data