Security Scan Report: mobile-connect.pages.dev

Site favicon
Submitted: Sep 29, 2026, 12:54:13 AMCompleted: Sep 29, 2026, 12:54:47 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 52%

5
Risk Score

A bare 'Loading' interstitial on a free pages.dev subdomain with obfuscated URL params and a fetch to an unranked host. No forms, no malware or IoC hits, so no definitive phishing evidence, but nothing legitimate either.

Risk Factors (5)
Free shared hosting subdomain (pages.dev) whose actual creation date cannot be verified
Unranked domain with no reputation footprint
Minimal auto-generated content with no functional purpose beyond loading
Outbound fetch to an unranked external host name suggesting bot/telemetry exfiltration
Copied Google copyright notice on a non-Google site
Safety Factors (5)
No credential, password, disguised-password or payment fields (0 forms on the page)
No JavaScript malware patterns, no YARA high-precision hits, no known-kit match
No Indicators of Compromise matched against the page or its resources
Privacy Policy and Terms of Service links present
All IDS alerts are informational categories, not phishing/malware/C2 signatures
Domain age information unavailable

Details

Page Title

Loading Page

Scan Type

public

Domain Name Analysis

The domain name 'mobile-connect.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'mobile-connect'. The core label 'pages' covers 5 characters with two vowels and 3 consonants. It segments into one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mobile-connect.pages.dev/?iduser=TkRnME13PT0=&HZ=xH0IE

Page Load Overview

0.48s
Total Load Time
11 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:134 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
news media journalism
40%
government public service
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6172.66.47.99Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.151.119Google · CDNUnited States
AS15169Google LLC
0104.26.12.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.13.100Google · CDNUnited States
AS15169Google LLC
0142.251.153.119Google · CDNUnited States
AS15169Google LLC
0104.26.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.13.138Google · CDNUnited States
AS15169Google LLC
0172.66.44.157Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
68--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F982C1E93696300B22FCED8FDB3585FB069854B214A7B41EBE4E74E523705E88DB2453

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:1Q5fVLFovLJwpIGl3k7U4ebcT3Kn/QFyaYh5rfMSbOakeGGgVVQ:2F7IGl3kg4ebcTVYj1bOakeGtVVQ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17897:8EYQohooMRgkAgBRgF4EJwBh0FYQYRKGiIKQXtMBECEZ6gQElgjgKApBhEK/AYoVh0iuoI6gB8AIqkAVUOoSUAKQohirCE4O

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000083c3c000000
Perceptual Hash:cc3333ccce3331cc
Difference Hash:0000102a20100000
Wavelet Hash:c0c0f4fcf8f0f0f0
Color Hash:#936b1f

Other Hashes

Crop Resistant:0000102a20100000

Scan History

Scan history not available

Unable to load historical scan data