Security Scan Report: brilliant-arithmetic-84258c.netlify.app

Redirected to:
https://brilliant-arithmetic-84258c.netlify.app/
Site favicon
Submitted: Oct 6, 2026, 1:45:17 AMCompleted: Oct 6, 2026, 1:45:57 AMpubliccompleted

This website contacted 2 IPs in 1 country across 1 domain to perform 5 HTTP transactions. The main domain is brilliant-arithmetic-84258c.netlify.app and was registered 8 years ago.

Submitted URL: http://brilliant-arithmetic-84258c.netlify.app/

Effective URL:

https://brilliant-arithmetic-84258c.netlify.app/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Cloned Aruba Mail webmail login on a random free Netlify subdomain, collecting email/password credentials; flagged by phishing threat intel and IDS as a possible phishing landing. Enter no credentials.

Risk Factors (5)
Impersonation of another entity's brand (Aruba Mail) on a domain that is not Aruba's official domain
Credential-collecting login form (email + password) on a free hosting-platform subdomain
Threat-intel phishing match on the primary domain (single-source, unverified)
Randomly generated Netlify subdomain of unknown age, unranked in Cisco Umbrella
Network IDS heuristics repeatedly flag the host as a possible phishing landing
Domain age information unavailable

Details

Page Title

Sign in to Webmail - Aruba Mail

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'brilliant-arithmetic-84258c.netlify.app' is registered, featuring subdomain 'brilliant-arithmetic-84258c'. The second-level label 'netlify' is 7 characters long containing 2 vowels alongside five consonants. Segmentation suggests three words: net, li, fy. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://brilliant-arithmetic-84258c.netlify.app/

Page Load Overview

1.43s
Total Load Time
667 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:798 chars
Detector Agreement:67%

Website Classification

Primary Category

government public service26% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
26%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
335.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
263.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
52--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T181468470DDE22442460F9BE6E26F72F9ED3438A752653D1EE40F78C4D7A910A7D82839

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

49152:Jj4cka38YcyrxzJKLq6MyDhanWCdVrIxT9aQxN3:Y

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5678300:5OkgYngBTSMRITEeCaAKJ0QE4EHahCKRAXTUhjDw5wW4UMQOjQCoGAFCRMEgKAjQjAgAiWRUEMgyAcVgIphGYmsiHFJAFwYE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff8f8f8b8bffffff
Perceptual Hash:b939c6c62dc2c23d
Difference Hash:ed3a381616b94410
Wavelet Hash:e18383830121ffff
Color Hash:#8f6ce0

Scan History

Scan history not available

Unable to load historical scan data