Security Scan Report: docs.google.com

Redirected to: https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ/viewform?edit_requested=true

Site favicon
Submitted: Oct 25, 2025, 9:40:24 AMCompleted: Oct 25, 2025, 9:41:52 AMpubliccompleted
Loading additional data...

Summary

This website contacted 14 IPs in 2 countries across 7 domains to perform 29 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ

Effective URL: https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ/viewform?edit_requested=trueRedirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing page impersonating DHL using Google Forms – high risk.

Risk Factors
Brand impersonation (DHL) on a non‑official domain
Social engineering with threatening delivery‑failure message
Use of a legitimate service (Google Forms) to disguise a phishing page
Domain age information unavailable

Details

Page Title

Delivery Attempt Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

Domain 'docs.google.com' uses the commercial generic top-level domain (.com) and includes subdomain 'docs'. Its registrable label 'google' stretches across 6 characters with three vowels and three consonants. Segmentation suggests 1 word: google. Average segment length settles at 6 characters. 'google' most often appears in Sinhala. It also appears in Danish and English contexts. Taken together, it feels Sinhala with single-word simplicity.

Screenshot

Security scan screenshot of https://docs.google.com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ

Page Load Overview

46.31s
Total Load Time
29
HTTP Requests
7
Domains
982 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:950 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3142.250.184.193United States
AS15169GOOGLE
2142.250.185.195United States
AS15169GOOGLE
2142.250.185.227United States
AS15169GOOGLE
2142.250.185.78United States
AS15169GOOGLE
2172.217.18.10United States
AS15169GOOGLE
2142.250.185.131United States
AS15169GOOGLE
2142.250.184.206United States
AS15169GOOGLE
22a00:1450:4001:828::2001Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:827::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
22a00:1450:4001:80f::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
2914--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D3C3DC2181F1AC6AA5574876FD32EB4D39CD939BE38EC423EE7B0F66E7E0441211570A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:skkQ6FAt0j6rqto2GHpkxGj36b7PG0j/jJ6+inlqj9KhAb1scS+W1e4:FIbI+BY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:121296:MGFAAKEAUCCIAgwlAgwuQBuAElNCoANGhEJ4HAxACSlCwiLCCyGKwMAAACV2gNDAC0EAghEERaDSwACKAYBAWAEYCgCYXJg2

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3efffffffffff
Perceptual Hash:b333766464cccc99
Difference Hash:8e8e581070607070
Wavelet Hash:00000d0d3d3d3d3c
Color Hash:#1f3e93

Other Hashes

Crop Resistant:8e8e581070607070

Scan History

Scan history not available

Unable to load historical scan data