Security Scan Report: hf-8zk.pages.dev

Site favicon
Submitted: Sep 27, 2026, 12:50:36 PMCompleted: Sep 27, 2026, 12:52:32 PMpubliccompleted

This website contacted 5 IPs in 3 countries across 6 domains to perform 19 HTTP transactions. The main domain is hf-8zk.pages.dev and was registered 40 years ago.

Submitted URL: https://hf-8zk.pages.dev////%22https:////6.at.atwola.com//adlink%7C5113.1%7C5043043%7C0%7C5112%7CAdId=11146745;BnId=1;guid=9slkin1gpn6fu&b=4&d=dsEdG7FtYFGGYz9oEjMo&s=4f&i=em3Lgw_lUX_mVsy6EwTm;itime=739915162;kvsecure-darla=4-10-0%7Cysd%7C2;kvsecure=true;kvmn=y963896142;kvy-bucket=mbr-push-untrusted-ar%2Cmbr-fido-1fa-login%2Cmbr-rcscore-thresh

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed phishing kit on a Cloudflare Pages subdomain impersonating AT&T Mail/Yahoo, harvesting username and passwords and exfiltrating them cross-origin to 2fa.support. Flagged twice by Safe Browsing.

Risk Factors (5)
Brand impersonation of AT&T Mail / Yahoo on an unrelated Cloudflare Pages subdomain
Cross-origin credential exfiltration to 2fa.support
Multiple password fields disguising a login harvest
Safe Browsing Social Engineering detections
Favicon impersonation (Yahoo favicon on non-Yahoo host)
Domain age information unavailable

Details

Page Title

Yahoo

Scan Type

public

Domain Name Analysis

You're looking at domain 'hf-8zk.pages.dev' on the developer-focused generic top-level domain (.dev) with subdomain 'hf-8zk'. The second-level label 'pages' is 5 characters long containing 2 vowels alongside three consonants. Segmentation suggests one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://hf-8zk.pages.dev////%22https:////6.at.atwola.com//adlink%7C5113.1%7C5043043%7C0%7C5112%7CAdId=11146745;BnId=1;guid=9slkin1gpn6fu&b=4&d=dsEdG7FtYFGGYz9oEjMo&s=4f&i=em3Lgw_lUX_mVsy6EwTm;itime=739915162;kvsecure-darla=4-10-0%7Cysd%7C2;kvsecure=true;kvmn=y963896142;kvy-bucket=mbr-push-untrusted-ar%2Cmbr-fido-1fa-login%2Cmbr-rcscore-thresh

Page Load Overview

2.82s
Total Load Time
920 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Text Length:164 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software75% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
75%
social media network
71%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
387.248.119.251United Kingdom
AS203220Yahoo-UK Limited
3144.161.106.163United States
AS797AT&T Services, Inc.
387.248.119.252United Kingdom
AS203220Yahoo-UK Limited
3188.125.72.139Dublin, Leinster, Ireland
AS34010Yahoo-UK Limited
195--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1ABD21BB6C475C47B120D0C8526F8FF257CAB520B9A4BBBD179AF8B096F40D6B850394D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:0bf1yHiszIplfIBcOoJBsThOzE1dvjAbGJB8eZLYbY/:05yHiA4lfIBcOoT68zE1dbz8qYbY/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29406:K0AAySOiBExABGhICYlECRCxCTwmmEBjMQiCAAhcQXw2IECHxhwISAUjwJB4AriQAoaREQAgMUYEEJJHVAmJEAAQsBoAiRcQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7ee6e6e6fefefefe
Perceptual Hash:f7238d8d2327898d
Difference Hash:ca2a4e4c320a0202
Wavelet Hash:7e60d8c0d8c0fcfc
Color Hash:#a787c5

Other Hashes

Crop Resistant:ca2a4e4c320a0202

Scan History

Scan history not available

Unable to load historical scan data