Security Scan Report: server-index-page--gutpunchedac.replit.app

Submitted: Sep 13, 2026, 11:52:43 PMCompleted: Sep 13, 2026, 11:53:01 PMpubliccompleted

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 2 HTTP transactions. The main domain is server-index-page--gutpunchedac.replit.app and was registered 18 years ago.

Submitted URL: https://server-index-page--gutpunchedac.replit.app/forgotpassword.html

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Ephemeral replit.app subdomain with a /forgotpassword.html path and a single-source phishing report. Page is a dead Replit placeholder with no live forms, but the address/path match phishing infrastructure — treat as high-risk.

Risk Factors
Single-source (unverified) phishing threat-intel match on the primary domain
Forgot-password URL path consistent with credential-phishing kit structure
Free/instant hosting subdomain with no attributable domain age
Domain age information unavailable

Details

Page Title

This app isn't live yet

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(52%)

Domain Information

You're looking at domain 'server-index-page--gutpunchedac.replit.app' on the application-focused generic top-level domain (.app), featuring subdomain 'server-index-page--gutpunchedac'. Its registrable label 'replit' stretches across 6 characters containing two vowels alongside four consonants. Tokenizing the label suggests two words: rep, lit. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://server-index-page--gutpunchedac.replit.app/forgotpassword.html

Page Load Overview

0.49s
Total Load Time
4
HTTP Requests
3
Domains
22 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,270 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software52% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
52%
finance banking
52%
healthcare medical
49%
cryptocurrency blockchain
49%
documentation technical
48%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2142.250.154.95Google · CDNUnited States
AS15169Google LLC
134.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1142.250.154.94Google · CDNUnited States
AS15169Google LLC
43--

Page Statistics

4
Requests
3
Unique Domains
37.9 KB
Total Size

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D1414D4F1AA310497D43B8382FFB265571A6C4C7854EDD653E8C6248CFC91997DB239C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TxKKTt+TBOoR0j1Ob2f8YR8sN8PWfVcH5tsBnVR:TxK0UTCh7cWyZ6nVR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1878:AAACAABBAEBBAIQAICCAEAgSAAAAABAOAEAAAoCAgAQAAAAQAABAAACRAAACSBAAABAAAEAAAQAABAAAgwAAAgAAAUBAACMQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000018183c3c0000
Perceptual Hash:996666d93331cc66
Difference Hash:0008301230701400
Wavelet Hash:0c0c1c1c3c3c0000
Color Hash:#40bf75

Other Hashes

Crop Resistant:0008301230701400

Scan History

Scan history not available

Unable to load historical scan data