Security Scan Report: sp29ct-zormik-biz-lenvor-qastel.pages.dev

Redirected to:
https://sp29ct-zormik-biz-lenvor-qastel.pages.dev/send_appeal_request
Site favicon
Submitted: Jul 20, 2026, 12:45:05 PMCompleted: Jul 20, 2026, 12:46:25 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is sp29ct-zormik-biz-lenvor-qastel.pages.dev and was registered NaN years ago.

Submitted URL: https://sp29ct-zormik-biz-lenvor-qastel.pages.dev/rtyu-iopj-qewr-thjm?welcome=109837067514153&idnp=109837067514153&name_idnp=Help%20for%20You%20-%20Rosemary%20Brown

Effective URL: https://sp29ct-zormik-biz-lenvor-qastel.pages.dev/send_appeal_requestRedirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Page uses Meta branding with a known phishing kit, posing a high‑risk credential phishing threat.

Risk Factors
Brand impersonation on mismatched domain
Known phishing kit fingerprint
Unranked hosting subdomain
Domain age information unavailable

Details

Page Title

Meta for Business | Page Appeal

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'sp29ct-zormik-biz-lenvor-qastel.pages.dev' on the developer-focused generic top-level domain (.dev) with subdomain 'sp29ct-zormik-biz-lenvor-qastel'. The second-level label 'pages' is 5 characters long split between 2 vowels and three consonants. Breaking it apart gives 1 word: pages. The median word length lands at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sp29ct-zormik-biz-lenvor-qastel.pages.dev/rtyu-iopj-qewr-thjm?welcome=109837067514153&idnp=109837067514153&name_idnp=Help%20for%20You%20-%20Rosemary%20Brown

Page Load Overview

0.55s
Total Load Time
7
HTTP Requests
2
Domains
3.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,436 chars
Detector Agreement:80%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7188.114.96.3Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
71--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F862F6F109A827BD828F83A861237B88D29EB16FF6774014F6AD1BE41FC3C91D957584

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:gtkqR9dS1C4WemCDhakDi8On/mOsQVOZ0pugIqnrrXmA2QPuhaHQ6ltiW9Y:gthS1MqDfDJCVdpMqnrK82hwrl3Y

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:14931:KY5GMBIIwDAwjSUgAAAAThR4SkMRYiEgEUIBjRwKIEgyi0ikaAKCkKBMgARwCOYhGxRMsQSAwFKWDGAUkIEpoABLQgAAFJ2p

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:9b8fe3f7f3e3efe3
Perceptual Hash:e4983869c59367c7
Difference Hash:323e2eaec6cec8cf
Wavelet Hash:0b838383f3e1e7e1
Color Hash:#d279a0

Scan History

Scan history not available

Unable to load historical scan data