Security Scan Report: staging-h5.pages.dev

Redirected to: https://staging-h5.pages.dev/#/

Site favicon
Submitted: Dec 28, 2025, 6:29:27 AMCompleted: Dec 28, 2025, 6:31:31 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 3 domains to perform 63 HTTP transactions. The main domain is staging-h5.pages.dev and was registered NaN years ago.

Submitted URL: http://staging-h5.pages.dev/

Effective URL: https://staging-h5.pages.dev/#/Redirected

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

High‑risk site due to malicious primary domain indicator

Risk Factors
Primary domain pages.dev flagged as malicious
Domain age information unavailable

Details

Page Title

XCWallet

Scan Type

public

Language

🇺🇸

English

(53% confidence)

Category

finance banking

(57%)

Domain Information

The domain name 'staging-h5.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'staging-h5'. The second-level label 'pages' is 5 characters long with two vowels and three consonants. Segmentation suggests one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://staging-h5.pages.dev/

Page Load Overview

92.13s
Total Load Time
63
HTTP Requests
0
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:53%
Script Type:Latin
HTML Lang Attribute:zh-CN
Text Length:299 chars
Detector Agreement:100%
Language mismatch: Declared as zh but detected as en

Website Classification

Primary Category

finance banking57% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
57%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
45172.66.47.200United States
AS13335CLOUDFLARENET
1124.221.80.91UnknownUnknown
02--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T193D365E544552289A2338E5297DD8F684A2CE76380620CDE7356284F8FC6FDE33DA717

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:56uNQ3fdPwwanleMf72yMPkZ8PFwh1nAukdDO3Xyr5Ir5eh0dTDiRH6hlKGcHL/x:IkZgwh1nAukdDO3Xyr5Ir5eh0dTS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137666:I2fJFIIGgMTpJBEoCAIYGDAiS0BAJDMxjQijCIwKFFykQMChAhtaTFDIAASAQmAkPocDgQWQIUbFkmEkp2CJUkEOEBiEADAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00007effffffffff
Perceptual Hash:875a6a7239f4e099
Difference Hash:2969d45558ccf0aa
Wavelet Hash:000000b48fff7fff
Color Hash:#2d45d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data