Security Scan Report: forms.gle

Redirected to: https://docs.google.com/forms/d/e/1FAIpQLSeBaudL5FIiX0xtpecgpuliMnlRinPfk-XnkKxkoonTixCnqQ/viewform?usp=send_form

Site favicon
Submitted: Nov 22, 2025, 6:28:11 AMCompleted: Nov 22, 2025, 6:29:12 AMpubliccompleted
Loading additional data...

Summary

This website contacted 15 IPs in 2 countries across 8 domains to perform 26 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/YdKWhf42YBUzJnpY6

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSeBaudL5FIiX0xtpecgpuliMnlRinPfk-XnkKxkoonTixCnqQ/viewform?usp=send_formRedirected

The Cisco Umbrella rank of the primary domain is #9,953 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing page impersonating Canada Post; do not submit any information.

Risk Factors
Brand impersonation of Canada Post on a non‑official domain
Use of a Google Form to harvest personal data (name, address, tracking details)
Redirect via forms.gle (short URL) to a domain unrelated to the displayed brand
Domain age information unavailable

Details

Page Title

Delivery Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

Domain 'forms.gle' uses the .gle top-level domain and has no subdomain. Count 5 characters in 'forms' split between 1 vowel and 4 consonants. Splitting it apart reveals 1 word: forms. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://forms.gle/YdKWhf42YBUzJnpY6

Page Load Overview

1.18s
Total Load Time
26
HTTP Requests
8
Domains
956 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:773 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7216.58.206.67United States
AS15169GOOGLE
7142.250.186.131United States
AS15169GOOGLE
5142.250.185.206United States
AS15169GOOGLE
3142.250.186.170United States
AS15169GOOGLE
2142.250.186.35United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
1172.217.18.1United States
AS15169GOOGLE
12a00:1450:4001:829::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:81d::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:82f::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
2615--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19B73D80702116CBAEE6700E2D2455D0A7F9D133BB44761BAE2FC1FA63BDB8D9111636B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:G6CaUjSTGt0p4nCk0xzHrEV33bzqfLjJfSjuimszS+Wfv:M2t8uJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:73811:wJYiGQMdCKEEExwZgEGCA4MgNiJACABoBAKsYECAAITg4VMBjIXpIAwrQCuByYAoIqDKq3BNKYAFRTICOBBqAXY0OwiDRAdj

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3ffffefffffff
Perceptual Hash:b131676630ccce9e
Difference Hash:8e9e60949c681000
Wavelet Hash:c3c3cfdfc0c0f070
Color Hash:#8b79d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data