Security Scan Report: qatreser.netlify.app

Site favicon
Submitted: Sep 21, 2026, 7:50:02 PMCompleted: Sep 21, 2026, 7:50:29 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 58%

3
Risk Score

Netlify-hosted page wearing SAR (Saudi railway) branding on a non-official domain. Brand impersonation, but no forms, no IoC, no malware — moderate risk, not a confirmed phishing kit.

Risk Factors
Unofficial hosting of another organisation's brand identity (SAR) on a Netlify subdomain
Brand/domain mismatch on an unranked, unknown-age shared-hosting subdomain
Safety Factors
No credential, login, or payment forms detected (no harvestable data)
No Indicators of Compromise matches
No JavaScript malware (YARA) patterns
No network IDS alerts
No cross-origin credential exfiltration
Content is travel/tourism informational in tone
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 3
Domain age information unavailable

Details

Page Title

سار | رحلتك تبدأ هنا

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'qatreser.netlify.app' is registered, featuring subdomain 'qatreser'. The second-level label 'netlify' is 7 characters long containing two vowels alongside five consonants. Word splitting yields three words: net, li, fy. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://qatreser.netlify.app/

Page Load Overview

6.22s
Total Load Time
726 KB
Total Size

Language Analysis

Primary Language

🇸🇦Arabic
Code: ar
Confidence:80%
Script:Arabic
Direction:rtl

Detection Details

HTML Lang Attribute:ar
Text Length:170 chars
Detector Agreement:100%

Website Classification

Primary Category

travel tourism72% confidence
Type: static
Method: ml+structural

All Detected Categories

travel tourism
72%
adult content
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
663.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
335.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
3142.251.20.94Google · CDNUnited States
AS15169Google LLC
154--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1937184B14014043FC26F4FDAF2B1733CB0F3528EDA466400A6B95BA94FD2E96EA1E495

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:y235+vau3O6G9GcDT9Sauh4U85Bwfid+a1a7F64LNJQmFbWFnHvVe1psz/uyRpIt:y48yu3O1DT9Sf0Jk4sBCFSyzW0Gt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3720:AFAIJAIBEECmAgATgAAgYAKAABKBkAYIDAYAJYABAIAggABABBgAAFAcCBAEYAxDIAgQEAAAwQAAEUgADwCgRAUArgAQQEAk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f8f23039e8e0f4ff
Perceptual Hash:cb0fb470e90f17b0
Difference Hash:6084636393084813
Wavelet Hash:f0f03038e8e0f0ff
Color Hash:#bf9540

Scan History

Scan history not available

Unable to load historical scan data