Security Scan Report: kandugas.pages.dev

Site favicon
Submitted: Sep 22, 2026, 1:14:50 AMCompleted: Sep 22, 2026, 1:16:48 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 60%

4
Risk Score

SEO-spam content farm on a free pages.dev subdomain scraping hotel and celebrity content with no credential or payment forms, no IoCs, and no malware — suspicious but not confirmed malicious.

Risk Factors (3)
Low-quality scraped/auto-generated content farm on shared hosting platform
Unranked domain with unknown page creation date
Outbound booking funnel through link shortener (taplink.cc)
Safety Factors (6)
No Indicators of Compromise matches against the page or its resources
No JavaScript malware (YARA) patterns detected
No known malicious phishing kits identified in kit roster
No credential, password, or payment fields — no data harvesting form
No credential exfiltration or cross-origin credential submissions detected
Network IDS alerts are only informational/hosting-platform detections, not phishing or malware signatures
Domain age information unavailable

Details

Page Title

Noorus Hotel : You can use the following amenities: - Dukang

Scan Type

public

Domain Name Analysis

The domain name 'kandugas.pages.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'kandugas'. The core label 'pages' covers 5 characters with 2 vowels and 3 consonants. Breaking it apart gives one word: pages. Median word length is five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kandugas.pages.dev/post/noorus-hotel/

Page Load Overview

80.15s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:6,761 chars
Detector Agreement:60%

Website Classification

Primary Category

travel tourism62% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

travel tourism
62%
adult content
43%
healthcare medical
35%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.13.95Google · CDNUnited States
AS15169Google LLC
115.197.212.58Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1217.146.70.51Estonia
AS49604Zone Media OU
1217.146.69.26Estonia
AS49604Zone Media OU
123.45.97.77Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
1146.75.121.29Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
1104.16.78.6Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
199.84.152.98Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1178.176.128.203Russia
AS31133PJSC MegaFon
4634--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17131983E0C00D4372A1343B53179F75CF5C75A2DB242C860F5BA58A92ED2E81CD12495

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:Ja1NBm1kC0TNpCXz8mPVjEntWr0m5FwUngQ:Ja781k4VMJ1uH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1665:BIQAAIABAAAABgBAAAQAAAAgAAAAAAAACCAJAACAAAAAIAQCAAAAAAAQAAAgIIAUBABSAwQQQAgIAQAAAwAABgQIAAAIAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffdfc787c7ffc787
Perceptual Hash:b2d9c7cd322e3134
Difference Hash:283c3e2e9ed22e0f
Wavelet Hash:df878383c3cb8383
Color Hash:#78763a

Scan History

Scan history not available

Unable to load historical scan data