Security Scan Report: pub-389d64919a554cc4956fa6bcb19fb720.r2.dev

Submitted: Sep 29, 2026, 2:52:39 AMCompleted: Sep 29, 2026, 2:53:18 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Credential-harvesting webmail login dropped into a public Cloudflare R2 bucket. No legitimate webmail is hosted on open object storage — do not enter any email or password.

Risk Factors (4)
Credential (email + password) login form hosted on public cloud object storage
Generic 'Webmail - Login' branding impersonating a mail service with no verifiable provider domain
Shared-hosting tenant with unknown, unattributable page age (bucket exposed via r2.dev free namespace)
Unranked in Cisco Umbrella (not in top 1M)
Domain age information unavailable

Details

Page Title

Webmail - Login

Scan Type

public

Domain Name Analysis

Domain 'pub-389d64919a554cc4956fa6bcb19fb720.r2.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'pub-389d64919a554cc4956fa6bcb19fb720'. Its registrable label 'r2' stretches across 2 characters holding zero vowels versus 1 consonant, notching 1 digit. Word splitting yields two words: r, 2. Median word length comes out to one character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pub-389d64919a554cc4956fa6bcb19fb720.r2.dev/index(10).html

Page Load Overview

1.70s
Total Load Time
56 KB
Total Size

Language Analysis

Primary Language

🇰🇷Korean
Code: ko
Confidence:60%
Script:Hangul
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:49 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ko

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.18.50.34Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.46Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0172.217.114.4Google · CDNUnited States
AS15169Google LLC
0208.91.114.103Langley, British Columbia, Canada
AS40934Fortinet Inc.
0156.226.121.244Seychelles
AS135097LUOGELANG (FRANCE) LIMITED
0151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0143.204.181.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0172.217.115.4Google · CDNUnited States
AS15169Google LLC
69--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D492C6015DF108021343886ABF976546F552C847AA4FCD0CB6ACAF94EF85E63D8637BD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:r+RFYLaAyIF7/7lxYtO2SjGJXrd+rI0ML98+TL14IHYzUChzc7:r+RFcVyIFjkBSjkrsIYhlc7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:20297:nQs2IAKABGhDgjARCBUsWRCHCgAgAimMLIiIQgg9mZgQLLAaRAh7UvJAIuCYQJAQuhhRBaJAjDgXIQAEAgnQxgQhIBsqXLLg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c1c1810000000
Perceptual Hash:dd99666623393166
Difference Hash:0a22125226020202
Wavelet Hash:303838380e0e0e0e
Color Hash:#936b1f

Other Hashes

Crop Resistant:0a22125226020202

Scan History

Scan history not available

Unable to load historical scan data