Security Scan Report: effortless-macaron-6afef2.netlify.app

Submitted: Sep 23, 2026, 12:45:43 AMCompleted: Sep 23, 2026, 12:47:52 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Credential phishing page impersonating Hotmail/Microsoft on a netlify.app subdomain, harvesting the victim's email password under a fake 'secure document' pretext while logging their IP and device data. Do not enter any credentials.

Risk Factors (5)
Impersonation of Microsoft/Hotmail login on an unrelated netlify.app subdomain
Password harvesting form with pre-filled victim email address
External IP/geolocation lookup endpoints (ipapi.co, api.ipify.org) typical of phishing kits
Fabricated 'secure document' login pretext with persistent re-authentication prompts
Unknown subdomain creation date on a shared hosting platform
Domain age information unavailable

Details

Page Title

PORTAL - hotmail.com Mail Authentication

Scan Type

public

Domain Name Analysis

The domain 'effortless-macaron-6afef2.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'effortless-macaron-6afef2'. The registrable portion 'netlify' spans 7 characters containing 2 vowels alongside 5 consonants. Splitting it apart reveals 3 words: net, li, fy. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://effortless-macaron-6afef2.netlify.app/

Page Load Overview

14.06s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:407 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software71% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
71%
documentation technical
58%
government public service
43%
adult content
28%
news media journalism
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
635.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1104.26.8.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
152.6.161.198Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1142.251.154.119Google · CDNUnited States
AS15169Google LLC
1142.251.127.106Google · CDNUnited States
AS15169Google LLC
138--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T193A2C66A09F300257523E1783FFB93083671800B9506DC28B95C5794DFC8DA26ABFBE9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:18BIGRLRNm69g1vr1ntjbTe5VcQ2PBKemGOdDT5ghwhmVutAoSuCIdtLrJKR4q1d:uBIBfVKDE9X4sGMflldD+3P2bstQf2OR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21849:gEAFyY0AEBgoIpGLIuARZGEKHQjKyATDxhYHiUJ2AgYSFMDcMMwSOOE8DAAiAGZsFgAUdwHCCADAQJAbCSAxUAQgH1FAY8jH

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:008f00181a000000
Perceptual Hash:ddb86213dd60263e
Difference Hash:801224b2724ec7c2
Wavelet Hash:e0ff971e3e2260e0
Color Hash:#2d866d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data