Security Scan Report: docs.google.com

Site favicon
Submitted: Oct 25, 2025, 3:10:48 AMCompleted: Oct 25, 2025, 3:11:56 AMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 2 countries across 7 domains to perform 25 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ/viewform?edit_requested=true

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating DHL using a Google Form to harvest data.

Risk Factors
Brand impersonation on non‑official domain
Use of a malicious custom URL scheme (btips://)
Urgent/threatening language to pressure user action
Hidden form submission to Google Forms endpoint
Domain age information unavailable

Details

Page Title

Delivery Attempt Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

Domain 'docs.google.com' uses the commercial generic top-level domain (.com) and includes subdomain 'docs'. The second-level label 'google' is 6 characters long holding 3 vowels versus three consonants. Splitting it apart reveals 1 word: google. 'google' most strongly signals Sinhala. Secondary signals appear in Danish and English. Taken together, it feels Sinhala with single-word simplicity.

Screenshot

Security scan screenshot of https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ/viewform?edit_requested=true

Page Load Overview

38.38s
Total Load Time
25
HTTP Requests
7
Domains
822 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:950 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3172.217.18.3United States
AS15169GOOGLE
2142.250.185.227United States
AS15169GOOGLE
2142.250.186.110United States
AS15169GOOGLE
2142.250.185.74United States
AS15169GOOGLE
2172.217.18.1United States
AS15169GOOGLE
2142.250.181.238United States
AS15169GOOGLE
22a00:1450:4001:830::2001Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:827::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:831::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:82f::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
2512--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T164C3DC2181F1AC6AA5574876FD32EB4D39CD939BE38EC423EE7B0F66E7E0441211570A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:skkQ6FAt0j6rqto2GHpbanGd36b60Cdj/j2A+inlqj9K6Ab/ssS+W1e4:VP3bP+BJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:121262:gAr5AyAgAgQEEEQzAAAgTFEgAaoUIZyD1NIIpoKAWDCigQCCEPMAEAKkg+QMIAxgIA4ih0ASggER0kUAIAQICSEJxggBEZii

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c2c3fffffffffffe
Perceptual Hash:b333766464cccc99
Difference Hash:8e8e581870707070
Wavelet Hash:00002d3d3f3f3d3c
Color Hash:#1f3e93

Other Hashes

Crop Resistant:8e8e581870707070

Scan History

Scan history not available

Unable to load historical scan data