Security Scan Report: ml111.pages.dev

Submitted: Dec 29, 2025, 5:15:35 PMCompleted: Dec 29, 2025, 5:16:33 PMpubliccompleted
Loading additional data...

Summary

This website contacted 23 IPs in 3 countries across 15 domains to perform 53 HTTP transactions. The main domain is ml111.pages.dev and was registered NaN years ago.

Submitted URL: https://ml111.pages.dev/

AI Security Verdict

High Risk

Confidence: 95%

8
Risk Score

High‑risk phishing site impersonating Ookla Speedtest

Risk Factors
Malicious Indicators of Compromise match (pages.dev)
Brand impersonation on an unranked domain
Unranked domain presenting a major brand
Domain age information unavailable

Details

Page Title

Speedtest by Ookla - The Global Broadband Speed Test

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(61%)

Domain Information

Within the developer-focused generic top-level domain (.dev), 'ml111.pages.dev' is registered and includes subdomain 'ml111'. Count 5 characters in 'pages' with 2 vowels and three consonants. Splitting it apart reveals one word: pages. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ml111.pages.dev/

Page Load Overview

2.69s
Total Load Time
48
HTTP Requests
17
Domains
2.2 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,368 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical61% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
61%
technology software
53%
government public service
30%
news media journalism
29%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.18.87.42United States
AS13335CLOUDFLARENET
2142.251.140.170France
218.245.31.92United States
AS16509AMAZON-02
213.226.244.7Unknown
223.36.162.25Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2104.18.86.42Unknown
23.217.134.118Unknown
223.36.162.6Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2172.66.47.115United States
AS13335CLOUDFLARENET
2172.66.44.141United States
AS13335CLOUDFLARENET
4823--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T166F309F522BC535D908B875DEF36B608630FE0B7B5A689D5BB5D8F644B839E4E803840

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:xSCEG7s4yv4s0xE6J/CgbcVKzoKeMXKLnpI6dDcPXE+ymj6aslNzlbsjq0Aok3a/:bEb4bagbcVMaWUZD+3UbwnZT7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:168436:CE0AQtVBwMkPYktogUJAFCmBEoBICASyqcIgOgAEyBEwgkFigMkBMBA2AjaEKJQgteQQQQQwDBDSEKSPg4CDH8QXQAKBgihA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffffff0100
Perceptual Hash:aad522f132c7ca55
Difference Hash:9971616111010101
Wavelet Hash:6f3b3b3b01310100
Color Hash:#2dd2a6

Other Hashes

Crop Resistant:9971616111010101

Scan History

Scan history not available

Unable to load historical scan data