Security Scan Report: mobile-connect.pages.dev

Site favicon
Submitted: Sep 29, 2026, 6:52:05 PMCompleted: Sep 29, 2026, 6:52:38 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 62%

6
Risk Score

Content-free 'Loading' gateway on a Cloudflare Pages subdomain that passes a double-base64 user id to an unranked external backend and falsely displays a Google copyright. No credential or payment form was found, so risk is moderate rather than confirmed phishing.

Risk Factors (5)
Thin, content-free loading page used as a forwarding/redirect gateway
Double base64-encoded user identifier passed in the URL
Outbound fetch to unranked third-party domain (connect.robot-agachado.org)
False Google copyright attribution on a non-Google domain
Hosted on a free shared platform subdomain with unknown creation date
Safety Factors (5)
No credential, password or payment form fields detected (0 forms)
No Indicators of Compromise matched against the page or loaded resources
No YARA JavaScript malware patterns or known phishing-kit signatures
All scripts served from the site's own domain; no third-party script hosts
Terms of Service / Privacy Policy references present
Domain age information unavailable

Details

Page Title

Loading Page

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'mobile-connect.pages.dev' is registered, featuring subdomain 'mobile-connect'. The second-level label 'pages' is 5 characters long with two vowels and 3 consonants. It segments into 1 word: pages. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mobile-connect.pages.dev/?iduser=TkRjM013PT0=&k5=59DTM

Page Load Overview

0.40s
Total Load Time
11 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:134 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
news media journalism
40%
government public service
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6172.66.44.157Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.154.119Google · CDNUnited States
AS15169Google LLC
0104.26.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.250.154.139Google · CDNUnited States
AS15169Google LLC
0172.66.47.99Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.151.119Google · CDNUnited States
AS15169Google LLC
0172.67.74.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.250.154.101Google · CDNUnited States
AS15169Google LLC
68--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F982C1E93696300B22FCED8FDB3585FB069854B214A7B41EBE4E74E523705E88DB2453

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:1Q5fVLFovLJwpIGl3k7U4ebcT3Kn/QFyaYh5rfMSbOakeGGgVVQ:2F7IGl3kg4ebcTVYj1bOakeGtVVQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17897:8EYQohooMRgkAgBRgF4EJwBh0FYQYRKGiIKQXtMBECEZ6gQElgjgKApBhEK/AYoVh0iuoI6gB8AIqkAVUOoSUAKQohirCE4O

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000083c3c000000
Perceptual Hash:cc3333ccce3331cc
Difference Hash:0000102a20100000
Wavelet Hash:c0c0f4fcf8f0f0f0
Color Hash:#936b1f

Other Hashes

Crop Resistant:0000102a20100000

Scan History

Scan history not available

Unable to load historical scan data