Security Scan Report: forms.gle

Redirected to: https://docs.google.com/forms/d/e/1FAIpQLSdNG80lJLUJU16iyE06bxVqQf0UR7xW6CJNIPPf-tloz7gmVA/viewform?usp=send_form

Site favicon
Submitted: Nov 26, 2025, 11:34:23 PMCompleted: Nov 26, 2025, 11:36:56 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 8 domains to perform 26 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/s5FS9GLERtw5XSGw7

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSdNG80lJLUJU16iyE06bxVqQf0UR7xW6CJNIPPf-tloz7gmVA/viewform?usp=send_formRedirected

The Cisco Umbrella rank of the primary domain is #9,953 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

Phishing page impersonating Canada Post via a Google Form redirect.

Risk Factors
Brand impersonation (Canada Post) on a non‑official domain
Suspicious redirect from forms.gle to a generic Google Forms page
Potential collection of personal information via a phishing form
Domain age information unavailable

Details

Page Title

Canada Post Notification

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'forms.gle' uses the .gle top-level domain without a subdomain. The core label 'forms' covers 5 characters split between 1 vowel and four consonants. It segments into one word: forms. Median word length is five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://forms.gle/s5FS9GLERtw5XSGw7

Page Load Overview

0.91s
Total Load Time
26
HTTP Requests
8
Domains
962 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:797 chars
Detector Agreement:50%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7216.58.206.67United States
AS15169GOOGLE
7142.250.184.195United States
AS15169GOOGLE
4142.250.186.110United States
AS15169GOOGLE
3142.250.186.74United States
AS15169GOOGLE
2142.250.186.35United States
AS15169GOOGLE
1142.250.185.206United States
AS15169GOOGLE
1142.250.181.225United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
12a00:1450:4001:81c::2001Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:812::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
2616--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13573E8071211ACBEDE6701E2E5456A093F9D037BB0466179E2FC1FB23BD78DA111636B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:n6CaUjSTGt0p4nCk0xz5ct63lbvJ9ojIVijBwcOnh6Z4y:bjeMBt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:75171:iNAJeUAQ4oDGkClAS1QAKg0DBEk0AIsgBnOALpUbXE2Q2mARAwCCCWUjqmA7OA1I7AQRkaG4IQCBAxCAIQQBjEFCjJaoAFQS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:010001ffffffffff
Perceptual Hash:bf2b6ac4d4966268
Difference Hash:4b55174e0a466cc0
Wavelet Hash:00000080ffffbfff
Color Hash:#3e1f93

Scan History

Scan history not available

Unable to load historical scan data