Security Scan Report: forms.gle

Redirected to: https://docs.google.com/forms/d/e/1FAIpQLSfGBXwSdUELbdBhDqPSCRCu9a9o-M0rse3y4SHNMvudPNryiQ/viewform?usp=send_form

Site favicon
Submitted: Nov 27, 2025, 12:08:03 PMCompleted: Nov 27, 2025, 12:12:07 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 8 domains to perform 26 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/4ER1kGLLcmXesXkH8

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSfGBXwSdUELbdBhDqPSCRCu9a9o-M0rse3y4SHNMvudPNryiQ/viewform?usp=send_formRedirected

The Cisco Umbrella rank of the primary domain is #9,953 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 82%

7
Risk Score

Phishing page impersonating Canada Post; high risk despite legitimate Google hosting.

Risk Factors
Brand impersonation (Canada Post) on a domain not belonging to the brand
Phishing lure via fake delivery failure notice
Form used to harvest personal information
Domain age information unavailable

Details

Page Title

Delivery Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'forms.gle' uses the .gle top-level domain while skipping any subdomain. The registrable portion 'forms' spans 5 characters with one vowel and 4 consonants. It segments into 1 word: forms. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://forms.gle/4ER1kGLLcmXesXkH8

Page Load Overview

1.14s
Total Load Time
26
HTTP Requests
8
Domains
957 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:773 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11216.58.206.78United States
AS15169GOOGLE
7142.250.186.131United States
AS15169GOOGLE
7142.250.186.163United States
AS15169GOOGLE
5142.250.185.206United States
AS15169GOOGLE
3142.250.186.74United States
AS15169GOOGLE
2142.250.185.131United States
AS15169GOOGLE
1142.250.186.65United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
12a00:1450:4001:804::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:810::2001Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
2616--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13373D80706116CBAEF6700E2D1855D0A3F5D137BB046A17AE3FC1FA23BDA9DA111636B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:E6CaUjSTGt0p4nCk0xzCv2F3b3b+4p7jIc9jsi5biK9N4BC:rDPBsO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:74077:BAgWUplRtGG0BCAQC6GwJBAgEwEMRtAgwJggqqBIPFYJmkmIEciBOBSCCRFmSMAAQERQAE5JFAgULbaDgGnCaAjAMB4KYU8p

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:010001ffffffffff
Perceptual Hash:bf2b6ad085d46362
Difference Hash:4f55173a72586243
Wavelet Hash:00000080ffffffbf
Color Hash:#798cd2

Scan History

Scan history not available

Unable to load historical scan data