Security Scan Report: php-web-server--unitmexi.replit.app

Submitted: Sep 30, 2026, 9:50:41 AMCompleted: Sep 30, 2026, 9:51:17 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

WhatsApp-branded phone-number validation page on a replit.app subdomain, flagged by Google Safe Browsing for social engineering and by threat intel for phishing — classic messaging-account takeover lure. Avoid and report.

Risk Factors (5)
WhatsApp brand impersonation on an unrelated host (replit.app free subdomain)
Google Safe Browsing Social Engineering detection
Indicators of Compromise match — primary domain reported as phishing (PhishDestroy, single-source)
Phone-number collection form consistent with messaging-app account takeover
External IP-lookup (ipapi.co) call typical of phishing kits that profile victims
Domain age information unavailable

Details

Page Title

Validación

Scan Type

public

Domain Name Analysis

The domain 'php-web-server--unitmexi.replit.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'php-web-server--unitmexi'. The core label 'replit' covers 6 characters holding two vowels versus four consonants. Word splitting yields 2 words: rep, lit. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://php-web-server--unitmexi.replit.app/index1.html

Page Load Overview

1.27s
Total Load Time
561 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:365 chars
Detector Agreement:100%

Website Classification

Primary Category

real estate property54% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

real estate property
54%
healthcare medical
27%
adult content
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
334.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
235.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2142.251.14.95Google · CDNUnited States
AS15169Google LLC
2142.250.154.94Google · CDNUnited States
AS15169Google LLC
2104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
157--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T116517A0054F0CCB242EB1CCD56A27C2A9AF9831792124748F67E4BFA0FB6E5ED133415

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:s85wZOeDG0l6wIq8GDPZmYHO+WbkGkKA/d1ND:75wZOcG0l6wIqSEhKP6PD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2958:AgBEAAgABACEkABhSJAYIYAABwAEBAAISAAEAQBiAACNEAAEDEZARAABIACIAAACIHgABAkABkRAgAAQgkIECAABAqAgEUAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7e7e7fffe
Perceptual Hash:f788dd22558877a2
Difference Hash:00000c084d4c000c
Wavelet Hash:0f0f070727270f0e
Color Hash:#c58796

Other Hashes

Crop Resistant:00000c084d4c000c

Scan History

Scan history not available

Unable to load historical scan data