Security Scan Report: 954dcd7b.ws-4f4.pages.dev

Submitted: Jan 19, 2026, 9:55:05 PMCompleted: Jan 19, 2026, 9:56:14 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 18 HTTP transactions. The main domain is 954dcd7b.ws-4f4.pages.dev and was registered NaN years ago.

Submitted URL: https://954dcd7b.ws-4f4.pages.dev/nas/

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

Phishing page impersonating PayPal with hidden and disguised password fields; do not submit any data.

Risk Factors
Brand impersonation (PayPal) on an unrelated domain
Disguised password fields (type='text' with password placeholder)
Hidden password field
Unicode evasion technique in form fields
Credential‑harvesting form on a suspicious domain
Domain age information unavailable

Details

Page Title

Order Summary - PayPal

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

e-commerce shopping

(37%)

Domain Information

The domain name '954dcd7b.ws-4f4.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain '954dcd7b.ws-4f4'. Count 5 characters in 'pages' holding 2 vowels versus 3 consonants. Breaking it apart gives one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://954dcd7b.ws-4f4.pages.dev/nas/

Page Load Overview

0.47s
Total Load Time
18
HTTP Requests
3
Domains
32 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,861 chars
Detector Agreement:75%

Website Classification

Primary Category

e-commerce shopping37% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

e-commerce shopping
37%
finance banking
35%
documentation technical
27%
technology software
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6172.67.180.104United States
AS13335CLOUDFLARENET
6104.18.34.93United States
AS13335CLOUDFLARENET
6188.114.96.3United States
AS13335CLOUDFLARENET
183--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C692E96040F845B7619381E1AAE6AE0B3EC9D603CB0A45507AFC4BE55FDBD83CE2716D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:2gRGel2OJ2lfqBOflrJJJJJ4GbN2Ddtf1z:xRXTSfiOflrJJJJJ5bN2DLtz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:19456:IFFRFJJq7RQiKToAjVhBLFCJjkUDQUShCAqW+VNIoACKhFGjG1RGSAExLXkDUBJAypMxACFDIEGLoFkE1FoAZBB0AEqBkFSJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bfcfcbf1d3ffffff
Perceptual Hash:e93992866c4e96b3
Difference Hash:2394921216240000
Wavelet Hash:98ce4101c1f3f3f3
Color Hash:#c1d279

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data