Security Scan Report: nexuspirfsch.edgeone.dev

Submitted: Sep 21, 2026, 1:45:01 PMCompleted: Sep 21, 2026, 1:45:21 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed PayPal phishing kit on nexuspirfsch.edgeone.dev: harvests email, password, OTP and card details and exfiltrates them to Telegram — never enter credentials here.

Risk Factors (5)
Impersonation of PayPal brand on a non-PayPal, unranked hosting subdomain
Credential exfiltration to an external Telegram endpoint from client-side JavaScript
Harvests email, password, OTP code, and card details in a staged flow with fake countdown timers ('Time remaining: 05:00 minutes')
Deceptive multi-step page titled 'Login Page - Step Form with Loader and OTP' with noindex-free, no legitimate brand association
Hosted on an instant-publish platform namespace (.edgeone.dev) where the subdomain's true creation date is unknown
Domain age information unavailable

Details

Page Title

Login Page - Step Form with Loader and OTP

Scan Type

public

Domain Name Analysis

The domain name 'nexuspirfsch.edgeone.dev' uses the developer-focused generic top-level domain (.dev) and includes subdomain 'nexuspirfsch'. Its registrable label 'edgeone' stretches across 7 characters split between 4 vowels and 3 consonants. Segmentation suggests 2 words: edge, one. Average segment length settles at 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nexuspirfsch.edgeone.dev/

Page Load Overview

1.87s
Total Load Time
167 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:595 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce shopping67% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

e-commerce shopping
67%
finance banking
48%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
343.174.246.29Singapore
1104.26.2.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.43.142.6United Kingdom
AS16276OVH SAS
1104.16.79.73Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
143.174.247.29Singapore
1104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1210--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T171D0A797C900482499D0D7552DE1F12C25AFD86CF795DC41ADCD20798DC87EB88D3698

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3:qLJhquHbszvYl29CsAAbHblu+FYBzO9ePMvWKbrAF7UKX4q+gWLvj6vavvAI9kBz:q9hqIY7YUwfAbplg0O8+KlvjVvVuB9d

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:2e20ab4a87be956830a21b3b808f2bb0

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7efffffffe7
Perceptual Hash:b33388ccccce6666
Difference Hash:080c4d0c0c00000c
Wavelet Hash:20202020ffffff00
Color Hash:#9940bf

Other Hashes

Crop Resistant:080c4d0c0c00000c

Scan History

Scan history not available

Unable to load historical scan data