Security Scan Report: update-ssl.netlify.app

Site favicon
Submitted: Sep 26, 2026, 1:50:38 PMCompleted: Sep 26, 2026, 1:52:44 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Phishing landing on a free Netlify subdomain mimicking a cPanel/Webmail login; captured credentials are POSTed to an unrelated external host, and network IDS confirms a phishing credential-post kit.

Risk Factors (5)
Network IDS flagged the page as a phishing landing (ET PHISHING, credential POST)
Credential capture form (email + password) on an untrusted hosting-platform subdomain
Off-domain credential transmission endpoint (maillerpost.com/ty/postm.php)
Impersonation of a cPanel/Webmail login interface on a non-official domain
Hostname impersonates a security/service update ('update-ssl') unrelated to any legitimate provider
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Domain Name Analysis

The domain 'update-ssl.netlify.app' uses the application-focused generic top-level domain (.app) with subdomain 'update-ssl'. The core label 'netlify' covers 7 characters split between two vowels and 5 consonants. Splitting it apart reveals three words: net, li, fy. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://update-ssl.netlify.app

Page Load Overview

8.10s
Total Load Time
202 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:43%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,245 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

social_media50% confidence
Type: webapp
Method: structural

All Detected Categories

social_media
50%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
935.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1162.241.27.10Mumbai, Maharashtra, India
AS46606Unified Layer
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.13.95Google · CDNUnited States
AS15169Google LLC
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1810--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D82840268E914A3018664DCBDA5162D1E96E327860F0E44F17F4BE55FE7FDEEC8704A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:uyEiUELD/ZmXg8oWlleLOSFSF+ct+KqC+lVKMENEvmUGyeEUQpxvdKc:qiUWD/ZmXg8cOx+l6NEvRFzdKc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17672:JIChCMchGgR3LxIyCYAAaNAAVWBSLJVQGTCgACHxC9MDGqwDl2UaEMAPlnBDOBEAALAwQEoAKEgAYBGIUzQMqI4kIFABAdUg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7e7e7e7ffffff
Perceptual Hash:b333cccc669c9c98
Difference Hash:000c0c0c0c000800
Wavelet Hash:1f0707073f270f0f
Color Hash:#52862d

Other Hashes

Crop Resistant:000c0c0c0c000800

Scan History

Scan history not available

Unable to load historical scan data