Security Scan Report: defiflux.netlify.app

Site favicon
Submitted: Sep 26, 2026, 12:50:40 PMCompleted: Sep 26, 2026, 12:53:15 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Clone of a legitimate Web3 API vendor's site ('Blocklith') on a free, unranked netlify.app subdomain, with a single-source phishing report on its own domain. No forms seen, but treat as untrusted.

Risk Factors (4)
Single-source phishing threat-intelligence match on the primary domain
Clone of a legitimate Web3 API vendor's site content and testimonials under a different 'Blocklith' brand name
Unranked, unknown-age free hosting-platform subdomain inconsistent with the 'enterprise-grade' corporate claims
Inflated trust markers (fake logos/claim of 'trusted by biggest names', large user statistics) typical of fraudulent clone sites
Domain age information unavailable

Details

Page Title

Blocklith for Developers - Enterprise-Grade Web3 APIs

Scan Type

public

Domain Name Analysis

The domain name 'defiflux.netlify.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'defiflux'. Its registrable label 'netlify' stretches across 7 characters split between 2 vowels and five consonants. Breaking it apart gives three words: net, li, fy. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://defiflux.netlify.app/

Page Load Overview

20.73s
Total Load Time
3.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:19,547 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain92% confidence
Type: spa
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
92%
technology software
67%
corporate
35%
cryptocurrency
30%
news/blog
20%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
11104.18.4.212Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
11185.14.184.154Amsterdam, North Holland, Netherlands
AS14061DigitalOcean, LLC
11142.251.14.97Google · CDNUnited States
AS15169Google LLC
11142.251.20.94Google · CDNUnited States
AS15169Google LLC
1154.217.38.38Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
11192.178.183.95Google · CDNUnited States
AS15169Google LLC
11142.251.152.119Google · CDNUnited States
AS15169Google LLC
11104.16.79.73Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
27525--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B334C76178F61037126F52DB92527E187EC1A183CE049AE8B7FC529CCFB5D917AA360C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:2eapw6CuwYU4CpVRVwWt8oVfrGLVfrGnsFYZXvZdJ+IDHumAA7IrOs53W2x2LUgP:2xHNARee84AA7IrJo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:233525:QBSWkBogC0UE3MoXgggA7SFskxJMcIEgaDtiH0MFBwUSkAAVgAAmgkwTHRqAS4IAGZpyC5EgoAE4PCPVQRSKCLC1NwSTgApB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fec3e7ffffc7ff42
Perceptual Hash:f5c175d854d2549a
Difference Hash:8e868e6915866996
Wavelet Hash:7ec3c3e7ffc30000
Color Hash:#5b1f93

Other Hashes

Crop Resistant:8e868e6915866996

Scan History

Scan history not available

Unable to load historical scan data