Security Scan Report: benevolent-dolphin-f65907.netlify.app

Redirected to:
https://benevolent-dolphin-f65907.netlify.app/
Site favicon
Submitted: Jul 28, 2026, 1:45:10 PMCompleted: Jul 28, 2026, 1:46:13 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 2 countries across 6 domains to perform 2 HTTP transactions. The main domain is benevolent-dolphin-f65907.netlify.app and was registered NaN years ago.

Submitted URL: http://benevolent-dolphin-f65907.netlify.app/

Effective URL: https://benevolent-dolphin-f65907.netlify.app/Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating Roblox login; collect credentials on an untrusted Netlify subdomain.

Risk Factors
Brand impersonation on mismatched domain
Credential collection form
Unknown subdomain creation date
Cross‑origin POST to Telegram bot
Safe Browsing social engineering detection
Domain age information unavailable

Details

Page Title

Log in to Roblox

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate business

(87%)

Domain Information

Domain 'benevolent-dolphin-f65907.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'benevolent-dolphin-f65907'. Its registrable label 'netlify' stretches across 7 characters containing 2 vowels alongside five consonants. Tokenizing the label suggests three words: net, li, fy. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://benevolent-dolphin-f65907.netlify.app/

Page Load Overview

41.37s
Total Load Time
187
HTTP Requests
18
Domains
754 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:894 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business87% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
87%
entertainment media
69%
technology software
46%
corporate
35%
social_media
25%

Detected Features

Login Form
Search
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3223.32.239.34Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
3135.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
313.174.46.107Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
31128.116.5.3Frankfurt am Main, Hesse, Germany
AS22697Roblox
3118.66.112.38Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
3118.64.211.93Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1876--

Page Statistics

187
Requests
18
Unique Domains
3.4 MB
Total Size

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F7D3E9A7F705A53AAD4F5AF651087948C005BA62EE194AD8F4DCF3742FC9BF32A83105

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:fXmOJJCmvJl0WhfdcIHo2K/EGUcX4pWG8coC2n7dhU4b3mYtT8ht9f8PO4V2i6N+:fXZJ+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:130206:BSoaAgRCQAAAIKCaAMNSKIoiMosBANQlddj5Fg6GCQaA5ghmADLingCtLjUD7lgABQoKkZHIKGIUMgAIJEIQAEAkEQCMtVIQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:991919191901013d
Perceptual Hash:88cce263e2e3e2e3
Difference Hash:31b13131310d5169
Wavelet Hash:ff1d19191901017f
Color Hash:#2dd259

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data