Is pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev legit or a scam?
A malicious phishing page hosted on a temporary cloud storage domain, flagged by seven major antivirus engines for credential theft.
These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.
Analysis Summary
Critical risk detected
8 of 92 antivirus engines flag this page (7 outright malicious). Multiple independent checks — antivirus engines, browser safety blocklists, and threat databases — flagged this site. Don't enter personal information, deposit money, or download files.
Website Preview

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.
MT Intelligence
The site is hosted on a sub-domain of r2.dev, which is a common tactic for attackers to bypass filters by using a reputable cloud provider's infrastructure. Seven of our antivirus partners, including Emsisoft, ESET, and Sophos, have explicitly flagged this specific URL as phishing or malicious. The URL structure itself is a randomized string, which is a hallmark of temporary phishing campaigns rather than a legitimate business. While the underlying domain is established, this specific sub-page has a reputation score of zero and is actively being used for fraudulent activity.
Web Research Findings
Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.
Our security network has identified this URL as a phishing threat, with multiple major antivirus providers issuing active warnings.
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Domain & Encryption
Redirect Chain
- 1301http://pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev/
- 2404https://pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev/
Server Reputation
Avoid this site
Our automated review flagged enough risk that you should treat this site as unverified.
- Do not interact with pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev
Do not enter credentials, deposit money, download files, or install browser extensions from this site.
- Verify the business through independent channels
Check the company's social profiles, registry records, and search for recent news or reviews that are not hosted on the site itself.
- Never use irreversible payment methods
Crypto, gift cards, wire transfers, and cash apps offer zero buyer protection. Use a credit card or PayPal if you must pay.
- OpenShare your experience
If you have additional context, drop a comment below or post on the MalwareTips forum.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Safety FAQ
Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.
- Our automated security review flags pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
- No — pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev scored 1/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
- Yes. pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev presents a valid TLSv1.3 certificate issued by Let's Encrypt · E8, expiring in 41 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
- pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev is 3.9 years old, registered on 8/23/2022 through CloudFlare, Inc.. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
- 8 out of 92 antivirus engines in our malware network flagged pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev as malicious or suspicious (7 outright malicious). Even one detection is a meaningful signal.
- No. pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev is not currently listed on the major browser blocklist feeds that modern browsers use.
- pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev resolves to an IP operated by Cloudflare, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
- This is a permanent record of the scan run on June 29, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around pub-e55d00bbe3f740a58ef8bd646105b158.r2.dev have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.