Security Scan Report: loud-coffee-4d8r9iuu.edgeone.dev

Site favicon
Submitted: Sep 25, 2026, 1:45:11 PMCompleted: Sep 25, 2026, 1:45:47 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

PayPal-branded credential phishing page on an edgeone.dev subdomain: PayPal favicon and title, German login form harvesting email/phone + password, DevTools/right-click blocked, and visitor-profiling calls to IP-geolocation APIs.

Risk Factors
Brand impersonation of PayPal on an unrelated edgeone.dev subdomain
Login form collecting email/phone + password
Favicon copied from PayPal to mimic the real brand
DevTools and right-click blocking to hinder inspection
Cross-origin POST calls to multiple IP-geolocation services (ipapi.co, ipinfo.io, api.db-ip.com) typical of phishing kits profiling visitors
Unknown-age subdomain on a free instant-publishing platform
Domain age information unavailable

Details

Page Title

PAYPAL

Scan Type

public

Domain Name Analysis

The domain 'loud-coffee-4d8r9iuu.edgeone.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'loud-coffee-4d8r9iuu'. Its registrable label 'edgeone' stretches across 7 characters with four vowels and 3 consonants. Breaking it apart gives two words: edge, one. Expect 3.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://loud-coffee-4d8r9iuu.edgeone.dev/

Page Load Overview

1.36s
Total Load Time
215 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:203 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as de

Website Classification

Primary Category

technology software54% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
54%
finance banking
43%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
143.174.246.29Singapore
1104.17.207.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1116.202.166.112Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.208.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
1010--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EBC2D63E60F015266A13D0FDFAE7A304392AD0C3CA09DD15B9EC86496FC6E5A99D374C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:/ThL7V3WsS6Y+1XMFNrj5ufkrXhE0fs6soufE3/ieR:rhnntBMFxjEYXyUs6s/83Kw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:27660:0wASFEjBKBspQETwU0KAgGaGRQYSIDoERBDAcUwkZJKBiCqHIUAllnViwHAaCAkgEhmBxFpsh4ABFCCSkFM2UoCAwCcIAgHJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7ffe7e7ffffe7
Perceptual Hash:b3b3cccc26339989
Difference Hash:000c004d0c000808
Wavelet Hash:272727272727e700
Color Hash:#2d865f

Other Hashes

Crop Resistant:000c004d0c000808

Scan History

Scan history not available

Unable to load historical scan data