Security Scan Report: transcendent-muffin-d5ca11.netlify.app

Submitted: Sep 20, 2026, 12:45:34 PMCompleted: Sep 20, 2026, 12:46:29 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Fake Roblox login on a netlify.app subdomain using a '50 Robux' reward lure to harvest account credentials; flagged by Google Safe Browsing for social engineering. Do not enter credentials.

Risk Factors (7)
Impersonation of the Roblox brand on an unrelated netlify.app subdomain
Credential capture form (username/email + password) targeting Roblox accounts
Google Safe Browsing Social Engineering threat flag
Free instant-subdomain hosting (.netlify.app) with unknown actual page creation date
Fake reward ('50 Robux') incentive used as a phishing lure
Unranked domain with no Cisco Umbrella reputation
Multiple INFO-level ET HUNTING Suricata alerts for a suspicious Netlify-hosted phishing landing
Domain age information unavailable

Details

Page Title

Login - Roblox

Scan Type

public

Domain Name Analysis

The domain 'transcendent-muffin-d5ca11.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'transcendent-muffin-d5ca11'. The second-level label 'netlify' is 7 characters long holding two vowels versus five consonants. Splitting it apart reveals three words: net, li, fy. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://transcendent-muffin-d5ca11.netlify.app/

Page Load Overview

2.26s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:50%
Script:Unknown
Direction:ltr

Detection Details

Text Length:338 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam49% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

phishing scam
49%
social media network
48%
entertainment media
42%
adult content
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
135.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
22--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16ED1C6A7A2E324233557D46827E76A443124C013A50BCE693F9C7355CF85BD64EA3B8C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:/rqUvKvRu++xHYTXxo2tnrWHZD+XkDnx3i66jyfkpUFeT9edsBj1YNj:/rqUyv2ieGha

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6417:CG5JIEEBIIoRBSKCImCAQtMEXSQYwQMDUyRAAACgFQoAAAwGwBRjIQyEFg/CKAAIrMCBAzEJAHVYEgCBAMAUICJUhUVDIESG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:cc663399cc669999
Difference Hash:100c323232300800
Wavelet Hash:0f0f1f1f3c3c0c0c
Color Hash:#d2797e

Other Hashes

Crop Resistant:100c323232300800

Scan History

Scan history not available

Unable to load historical scan data