Security Scan Report: pikufy.netlify.app

Site favicon
Submitted: Sep 24, 2026, 1:45:40 PMCompleted: Sep 24, 2026, 1:47:02 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 65%

5
Risk Score

Spotify-branded clone on a free netlify.app subdomain with no attribution. No forms or credential capture detected, so risk is limited to brand impersonation rather than active phishing.

Risk Factors (3)
Impersonation of a different entity's brand (Spotify) on an unrelated hosting-platform subdomain
Hosting-platform subdomain where the effective page age is unknown and could be minutes old
No attribution or disclaimer that this is an unofficial third-party page
Safety Factors (5)
No credential, password or payment form collected in the captured DOM
No Indicators of Compromise matches against the page or its resources
No JavaScript malware (YARA) patterns, no obfuscation and no credential-exfiltration behaviour
No network IDS alerts, no Safe Browsing hits and no known malicious kit signature
Content is a static media/entertainment layout with no data-capture functionality detected
Domain age information unavailable

Details

Page Title

Spotify - Home - for everyone

Scan Type

public

Domain Name Analysis

Domain 'pikufy.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'pikufy'. Count 7 characters in 'netlify' split between two vowels and five consonants. Tokenizing the label suggests three words: net, li, fy. Average segment length settles at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://pikufy.netlify.app/

Page Load Overview

0.99s
Total Load Time
24 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:179 chars
Detector Agreement:100%

Website Classification

Primary Category

entertainment media85% confidence
Type: static
Method: ml+structural

All Detected Categories

entertainment media
85%
technology software
55%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1063.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1035.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
202--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15FA1212100F6946B469280D17EA06B2FBFC6DA53CA6B2A017AED1FD41FC3C47ED67108

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TPcTGhwraeC/nkFhcNTRGuQJhJGcPbJagJsPIBsHMgMh3dVM5:T0TGhBsWN1GdT0cTXePIBcMTh3A

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4932:RGAYBEQUCjYigICDAAEwBBAECPwBIlAQgIGhGZhEgisBBRIEIwAAQQSAAFAAACBAAIAUAEAOgYDAMAAMiBREBCABCQkGIAoG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:bfa0000000001f3f
Perceptual Hash:8f6a8f6a8eaa8aa8
Difference Hash:6d68b0a0a080a06a
Wavelet Hash:bfb310100c0c1f3f
Color Hash:#bf9540

Other Hashes

Crop Resistant:6d68b0a0a080a06a

Scan History

Scan history not available

Unable to load historical scan data