Security Scan Report: thecourierguy3678.netlify.app

Redirected to:
https://thecourierguy3678.netlify.app/
Site favicon
Submitted: Jul 23, 2026, 1:45:25 AMCompleted: Jul 23, 2026, 1:48:37 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 2 HTTP transactions. The main domain is thecourierguy3678.netlify.app and was registered NaN years ago.

Submitted URL: http://thecourierguy3678.netlify.app/

Effective URL: https://thecourierguy3678.netlify.app/Redirected

AI Security Verdict

Low Risk

Confidence: 78%

3
Risk Score

The site impersonates The Courier Guy, uses an unknown‑age Netlify subdomain, and solicits payment, indicating a high‑risk phishing scam.

Risk Factors
Brand impersonation of a known courier service
Unknown subdomain age on a hosting platform
Payment request on an untrusted domain
Lack of reputable domain ranking
Safety Factors
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 7 to 3
Domain age information unavailable

Details

Page Title

The Courier Guy

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

finance banking

(54%)

Domain Information

The domain 'thecourierguy3678.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'thecourierguy3678'. The second-level label 'netlify' is 7 characters long holding 2 vowels versus five consonants. Splitting it apart reveals 3 words: net, li, fy. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://thecourierguy3678.netlify.app/

Page Load Overview

1.74s
Total Load Time
23
HTTP Requests
3
Domains
339 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:720 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking54% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
54%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9142.251.110.97Google · CDNUnited States
AS15169Google LLC
7157.240.0.6Frankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
763.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
233--

Page Statistics

23
Requests
3
Unique Domains
373.7 KB
Total Size

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D6145047E5B225F90B33923913CF958472688CABE802FDA9BACD94458F892FD0D13757

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:HGW+mSmOmSm8mSmRmSmxmSmImSmUmSmtMZeRMA3ZbQWXDdj3fhfsf9fWfMfif1fG:31qe7wCq

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:198682:NTBiAoAoNgERUCjJ0EeCUwStjCapBQAEDAAkVwoUYogA6KMXCSDQ0QcQFACJRsmAwJESMLEAGehsxiACxUyzoKBAEqHPAOcI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00b3b9c8c1f7ffff
Perceptual Hash:bc0187263853c77f
Difference Hash:da564393374c1200
Wavelet Hash:02b381c8c0f7fcfc
Color Hash:#48bf40

Other Hashes

Crop Resistant:da564393374c1200

Scan History

Scan history not available

Unable to load historical scan data