Security Scan Report: ggfg-ikmy.onrender.com

Site favicon
Submitted: Sep 16, 2026, 4:50:04 PMCompleted: Sep 16, 2026, 4:50:31 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed phishing kit impersonating gov.pl and multiple Polish banks, harvesting login/PESEL/bank credentials and exfiltrating them to a Telegram bot — do not enter any data.

Risk Factors
Brand impersonation of gov.pl on a non-official onrender.com subdomain
11 password fields across 12 forms collecting bank and identity credentials
Credential data exfiltrated to api.telegram.org and gvvbt.onrender.com via cross-origin POST
Deceptive 'Verification' CAPTCHA flow mimicking a government/identity portal
Impersonates numerous Polish banks' login pages within one page
Urgency language pressuring victims to submit data immediately
Domain age information unavailable

Details

Page Title

gov.pl - Serwis Rzeczypospolitej Polskiej

Scan Type

public

Domain Name Analysis

The domain name 'ggfg-ikmy.onrender.com' uses the commercial generic top-level domain (.com) and includes subdomain 'ggfg-ikmy'. The core label 'onrender' covers 8 characters containing 3 vowels alongside 5 consonants. Segmentation suggests two words: on, render. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ggfg-ikmy.onrender.com

Page Load Overview

3.01s
Total Load Time
769 KB
Total Size

Language Analysis

Primary Language

🇵🇱Polish
Code: pl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pl
Text Length:3,042 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking95% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
95%
government public service
79%
phishing scam
49%
adult content
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15216.24.57.7United States
AS397273Render
14216.24.57.15United States
AS397273Render
292--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F0D3A45772552846745B90A839F24F0B233A8113D205CE797AAC08B8CF8DBE5D6F37E9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:3O8K1KrhsxkLraIyCmontKfBtd0C08qyWdluhGDCXKZMc5x0GwxjUmW9:afxW9

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:136745:EQAkQLiqSAQFDDTULLWBgHAUEGXABg6zUFNxhVIAKCAQYAKAxghiiR31gqSEIOJAAQhovAigQaIBCAFwdRAYGhhICNkiA8Hl

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:99cc663333cccc99
Difference Hash:4cb2b2b2b2b2b24c
Wavelet Hash:2c181818d8d8d8e0
Color Hash:#b3e06c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data