Security Scan Report: br-zim.netlify.app

Redirected to:
https://br-zim.netlify.app/
Submitted: Sep 20, 2026, 12:45:06 PMCompleted: Sep 20, 2026, 12:45:27 PMpubliccompleted

This website contacted 2 IPs in 2 countries across 2 domains to perform 7 HTTP transactions. The main domain is br-zim.netlify.app and was registered 16 years ago.

Submitted URL: http://br-zim.netlify.app/

Effective URL:

https://br-zim.netlify.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Fake Zimbra Web Client login on a netlify.app subdomain that harvests username/password and posts them cross-origin to submit-form.com — brand impersonation credential phishing, backed by a phishing threat-intel match.

Risk Factors
Brand impersonation of Zimbra (official login look-and-feel) on an unrelated netlify.app subdomain
Password/credential capture form on a brand-mismatched host
Credentials submitted to a third-party cross-origin endpoint (submit-form.com) instead of a Zimbra server
Phishing threat-intelligence match on the primary domain
Free hosting-platform subdomain of unknown creation age — cannot be treated as established
Domain age information unavailable

Details

Page Title

Zimbra Web Client Sign In

Scan Type

public

Domain Name Analysis

The domain 'br-zim.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'br-zim'. The core label 'netlify' covers 7 characters with 2 vowels and five consonants. Word splitting yields 3 words: net, li, fy. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://br-zim.netlify.app/

Page Load Overview

0.97s
Total Load Time
182 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:738 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software64% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
64%
corporate business
39%
documentation technical
32%
government public service
28%
social_media
25%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
435.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
393.94.224.225Netherlands
AS25151Cyso Group B.V.
72--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T122B2E86625E518610AA370FC59CF111934B49C2B1009CE087DFC92A83FB5E7A52A7BFE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:gsjhRgFO3nhkxUT4OmYXhl2Ei0m5HDpupShi4i2iZi5iFieigiMiniHiNJci8i5:BjD3nhkxUT4Om6tc/oVHgA0v9BiCNJRr

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23906:kEEOQFA4IwgDAOgQo7glgRqAARDGRwiMI8ybICUAXy3pbaEQRWEJxMBAuGAGUCpAKAJQvLGYJCWgHISh9ABALoHUASRBCkLF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:99da26f689a4d923
Difference Hash:504cb2b2b232cef3
Wavelet Hash:f07cfeff1f980000
Color Hash:#93401f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data