Security Scan Report: forms.gle

Redirected to: https://docs.google.com/forms/d/e/1FAIpQLSeaS6lZfpEONKa04GaMvK8Wz15BFQeXc_LM_TzOY2SwYCUSow/viewform?usp=send_form

Site favicon
Submitted: Oct 25, 2025, 3:42:36 AMCompleted: Oct 25, 2025, 3:43:54 AMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 8 domains to perform 30 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/SFQnWs2z27NZDDux9

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSeaS6lZfpEONKa04GaMvK8Wz15BFQeXc_LM_TzOY2SwYCUSow/viewform?usp=send_formRedirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Phishing page impersonating Canada Post using a Google Form to harvest data.

Risk Factors
Brand impersonation on a non‑official domain
Phishing lure (delivery failure) to trick users
Data‑collection form hosted on unrelated Google domain
Domain age information unavailable

Details

Page Title

Delivery Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

Within the .gle top-level domain, 'forms.gle' is registered with no subdomain. The second-level label 'forms' is 5 characters long containing 1 vowel alongside 4 consonants. It segments into 1 word: forms. 'forms' most strongly signals English. Usage also turns up in Chinese (Pinyin) and Tamil contexts. Net impression: English phrase with single-word simplicity.

Screenshot

Security scan screenshot of https://forms.gle/SFQnWs2z27NZDDux9

Page Load Overview

47.11s
Total Load Time
30
HTTP Requests
8
Domains
957 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:773 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15142.250.186.42United States
AS15169GOOGLE
1142.250.186.65United States
AS15169GOOGLE
1142.250.181.238United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
1142.250.185.99United States
AS15169GOOGLE
1142.250.185.227United States
AS15169GOOGLE
1142.250.185.142United States
AS15169GOOGLE
1172.217.18.3United States
AS15169GOOGLE
12a00:1450:4001:811::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:813::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
3016--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19C63D80716105CBAEF6701E2E1855E0A3F9D133BB04660BAE6FC1FA33BDA9D91116367

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:RkkQ6FAt0j6rqto2GHpLJ2q33Bbr2/u8Yjj/mMjezsXS+WHv:NInOGex

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:73067:AQCIckYRQCtYAOlEHQGAiKlUIAZ4lkEAQL0WdBhWCFBAM+tIwBDDXUGC5gAh4gLEGIiAoAS4gAIgEKTMI6TWoAhSgTOBQtFT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3ffffefffffff
Perceptual Hash:b131676630ccce9e
Difference Hash:8e8e60909c681000
Wavelet Hash:c3c3cfdf00200000
Color Hash:#2d8386

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data