Security Scan Report: highspotmints072.netlify.app

Submitted: Sep 13, 2026, 11:47:37 PMCompleted: Sep 13, 2026, 11:48:14 PMpubliccompleted

Summary

This website contacted 8 IPs in 2 countries across 8 domains to perform 1 HTTP transaction. The main domain is highspotmints072.netlify.app and was registered 4 years 7 months ago.

Submitted URL: https://highspotmints072.netlify.app

AI Security Verdict

Confirmed Scam

Confidence: 94%

10
Risk Score

OpenSea-impersonating fake NFT airdrop on a netlify subdomain, wired to blockchain RPCs and flagged as a wallet drainer with critical EtherHiding exfiltration IDS alerts. Do not connect a wallet.

Risk Factors
Impersonation of OpenSea Pro on an unrelated, unranked netlify.app subdomain
Fake NFT 'airdrop' with implausibly large cash rewards ($3,000–$250,000) to induce wallet connection
Blockchain RPC connections paired with brand impersonation — wallet drainer behaviour
Critical IDS malware/exfiltration alert (ET MALWARE EtherHiding Exfil M2)
Single-source threat-intel report categorising the domain as a wallet drainer
Domain age information unavailable

Details

Page Title

OpenSea.io

Scan Type

public

Language

🇪🇸

Spanish

(50% confidence)

Category

unknown

(0%)

Domain Information

Within the application-focused generic top-level domain (.app), 'highspotmints072.netlify.app' is registered; it also runs on subdomain 'highspotmints072'. The second-level label 'netlify' is 7 characters long with two vowels and five consonants. Breaking it apart gives three words: net, li, fy. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://highspotmints072.netlify.app

Page Load Overview

12.38s
Total Load Time
8
HTTP Requests
8
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:27 chars
Detector Agreement:100%
Language mismatch: Declared as en-US but detected as es

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
135.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.20.39.96Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.59Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
88--

Page Statistics

8
Requests
7
Unique Domains
5.5 MB
Total Size

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T109C02BBEEC038C5808807EC8CCE4F118490CA3B4F001DE00FDE130687E497AE1C05780

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3:PouVWJhquIw2lyiIryyD/Z3FXMwQxYqAqRAdu6/GYlWX/+G+LGXI9kBbZWM:h4hqBHImq/ZVXLgYqAqJmW/5+VuB9d

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:86ce8d67593c5b6d891cec68951a53ee

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0305010d0dffff
Perceptual Hash:bb26c41bc9d0d2d6
Difference Hash:b60f2ddb59191980
Wavelet Hash:ff0101010d0ddfff
Color Hash:#ac539c

Scan History

Scan history not available

Unable to load historical scan data