Security Scan Report: transfer-doc-23dec5.netlify.app

Submitted: Sep 27, 2026, 12:45:21 AMCompleted: Sep 27, 2026, 12:46:36 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Fake WeTransfer page on a netlify.app subdomain that harvests email and password and POSTs them to the unrelated domain trentdavid.com. Classic credential phishing — do not enter any data.

Risk Factors (5)
Brand impersonation of WeTransfer on a non-official netlify.app subdomain
Credential (email + password) form submitting to a cross-origin, unrelated domain (trentdavid.com)
JavaScript disables DevTools/right-click and view-source; uses dynamic Function() code generation
Unranked domain with no legitimate reputation while claiming a major file-transfer brand
Decoy/mismatched content (stock-footage headers, 'Purchase Order.pdf') inconsistent with the WeTransfer brand
Domain age information unavailable

Details

Page Title

WeTransfer

Scan Type

public

Domain Name Analysis

The domain 'transfer-doc-23dec5.netlify.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'transfer-doc-23dec5'. Its registrable label 'netlify' stretches across 7 characters holding two vowels versus 5 consonants. Splitting it apart reveals three words: net, li, fy. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://transfer-doc-23dec5.netlify.app/

Page Load Overview

10.02s
Total Load Time
1.9 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:386 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical64% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
64%
finance banking
55%
e-commerce shopping
47%
technology software
47%
adult content
43%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
363.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
327.254.44.187Thailand
AS9891CS LOXINFO Public Company Limited.
335.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
93--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11BC533215F657F2B0AFC42AD316E2B8C09A58F268026A2F1F5DD32C74F46F06827716C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

49152:tbUToI0EftjZwOX/Jtk5uJes/AlwxHjOeGJ9k9t5S:h

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2605266:BKAWMBqYeAG8hqEMogisLMmXxiMPlDAgRxAABoiHYqIAEAERAFASQwowpEOIEASAAUABJxYzZA0ADUg0JLECeA8iGUAQGVma

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0808d8d8d8d838fc
Perceptual Hash:d83b033cf22cf0ae
Difference Hash:9bd0b2b2b2b2f2e8
Wavelet Hash:0908d8d8d8da7efc
Color Hash:#3a7863

Scan History

Scan history not available

Unable to load historical scan data