Security Scan Report: br-zim.netlify.app

Submitted: Sep 27, 2026, 3:50:41 PMCompleted: Sep 27, 2026, 3:51:22 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake Zimbra sign-in page on br-zim.netlify.app that impersonates Zimbra and exfiltrates entered usernames and passwords to submit-form.com. Confirmed credential phishing — do not enter any credentials.

Risk Factors (5)
Brand impersonation of Zimbra on a mismatched netlify.app subdomain
Password-harvesting login form submitting credentials to an external service (submit-form.com)
Primary-domain phishing report in threat intelligence
High-severity IDS alert for form exfiltration
Unranked domain on a shared hosting platform with unknown subdomain creation date
Domain age information unavailable

Details

Page Title

Zimbra Web Client Sign In

Scan Type

public

Domain Name Analysis

The domain 'br-zim.netlify.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'br-zim'. The core label 'netlify' covers 7 characters holding 2 vowels versus five consonants. It segments into three words: net, li, fy. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://br-zim.netlify.app/

Page Load Overview

4.18s
Total Load Time
181 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:738 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software64% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
64%
corporate business
39%
documentation technical
32%
government public service
28%
social_media
25%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
263.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
293.94.224.225Netherlands
AS25151Cyso Group B.V.
235.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
63--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FFB2D86625E518610AA370FC59CF111934B49C2B1009CE087DFC92A83FB5D7A56B7BFE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:gqjhRgFO3nhkxUT4OmYXhl2Ei0m5HDpupShi4i2iZi5iFieigiMiniHiNJci8i9:pjD3nhkxUT4Om6tc/oVHgA0v9BiCNJRH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23699:BAIaNLRw6IvBgDIMgGKlqKEHXEAACTHcyCUASAFKACJugIkCAm8HVcLFBJgAZoIIKSIA7hWgxtgENGgoocAXgiAECACUSlFC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:99da26f689a4d923
Difference Hash:504cb2b2b232cef3
Wavelet Hash:f07cfeff1f980000
Color Hash:#663a78

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data