Security Scan Report: paypal-login.netlify.app

Redirected to:
https://paypal-login.netlify.app/
Site favicon
Submitted: Sep 19, 2026, 1:45:02 AMCompleted: Sep 19, 2026, 1:45:21 AMpubliccompleted

This website contacted 7 IPs in 3 countries across 8 domains to perform 21 HTTP transactions. The main domain is paypal-login.netlify.app and was registered 21 years ago.

Submitted URL: http://paypal-login.netlify.app/

Effective URL:

https://paypal-login.netlify.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

PayPal phishing page on a Netlify subdomain: fake PayPal login harvesting email/password and exfiltrating them to an unrelated pythonanywhere.com endpoint. Do not enter credentials.

Risk Factors (5)
Brand impersonation of PayPal on a non-official domain
Credential harvesting form (email + password) with cross-origin submission to an unrelated host
PayPal favicon and copied PayPal meta/UI content on a third-party subdomain
HIGH-severity IDS phishing alert
No genuine relationship to PayPal infrastructure despite loading paypal.com assets
Domain age information unavailable

Details

Page Title

Log in to your PayPal account

Scan Type

public

Domain Name Analysis

The domain 'paypal-login.netlify.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'paypal-login'. Count 7 characters in 'netlify' holding 2 vowels versus 5 consonants. Breaking it apart gives 3 words: net, li, fy. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://paypal-login.netlify.app/

Page Load Overview

0.80s
Total Load Time
153 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:782 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical51% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
51%
government public service
43%
technology software
43%
social media network
40%
blog personal website
39%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
335.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
3146.75.123.1Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
363.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
3104.18.7.168Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
334.147.177.40Google · CDNCity of London, England, United Kingdom
AS396982Google LLC
3104.18.6.168Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3146.75.121.35Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
217--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C8D1E7DAB461F04E035210BB50BBF30AF279AA1E9E598890F0D4C1FD6CF4E6542B7E09

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:ewKGXYomTGfBZ2yzMPp7m6ejna4urzmVcW/vtXwIeg6yGfpyuqQb7lkWTGquqhqo:eVKWY67kaWcW/vSIegVmR7bZukNMKdT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6768:ARATECRAAKNkAMDCgAAHAEAYWDwDAGAgwVFCQgCDaCA0F8oFzAIKAAhlMHDwAAAFjPAiTCAgAGsIYwTIgAAmyQBIlAEADgCA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7ffffffe7
Perceptual Hash:b33399cc4e662699
Difference Hash:0c004d0c00000008
Wavelet Hash:3c242424c3cbff00
Color Hash:#69ac53

Other Hashes

Crop Resistant:0c004d0c00000008

Scan History

Scan history not available

Unable to load historical scan data