Security Scan Report: glowing-dolphin-d8959f.netlify.app

Submitted: Sep 18, 2026, 12:45:25 PMCompleted: Sep 18, 2026, 12:45:52 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phishing page impersonating Garena Free Fire on a free netlify.app subdomain, using a fake login form that sends passwords to formspree.io; flagged by Google Safe Browsing for social engineering.

Risk Factors
Impersonation of the Garena Free Fire brand on a domain that is not Garena's official site
Login form capturing email/username and password, submitted to an external form-backend the site owner controls
Google Safe Browsing Social Engineering detection
Password field present in the DOM but hidden from the rendered screenshot
Hosted on a free, unranked netlify.app subdomain with unknown actual creation date (platform apex age is not attributable to this page)
Domain age information unavailable

Details

Page Title

Garena Free Fire - Neo City & Login Akun

Scan Type

public

Domain Name Analysis

The domain 'glowing-dolphin-d8959f.netlify.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'glowing-dolphin-d8959f'. The second-level label 'netlify' is 7 characters long split between 2 vowels and five consonants. Tokenizing the label suggests three words: net, li, fy. Average segment length settles at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://glowing-dolphin-d8959f.netlify.app/

Page Load Overview

0.89s
Total Load Time
321 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:id
Text Length:888 chars
Detector Agreement:67%

Website Classification

Primary Category

social media network93% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
93%
technology software
25%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
435.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1104.26.2.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.217.208.95Google · CDNUnited States
AS15169Google LLC
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
174.125.29.95Google · CDNUnited States
AS15169Google LLC
1146.75.122.208Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
107--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E001CE334501D81202B088A32FA0F28C60DE7B57976A4DC4B8CA13F91E4EBA621D7E58

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hThKTGh1IbBa2aY5C/rXNFbByeCsFEhVG:9cTGhObBa2aeC/hdBFEhU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:809:gAAAAQAAgIAAAkAAACAAAQAAAABAAUAAAAAAAAAAAgAAAAAAgAAAAAAAAAIAAAAgAIBwAAAAAAIBAAAAAAABAQAAAABAAAIA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3d3d093d39180000
Perceptual Hash:8a8b33cece667831
Difference Hash:71fb9b6171334d31
Wavelet Hash:3d7f5bbd39190101
Color Hash:#d2ce79

Other Hashes

Crop Resistant:71fb9b6173334931

Scan History

Scan history not available

Unable to load historical scan data