Security Scan Report: preview.webflow.com

Site favicon
Submitted: Oct 27, 2025, 10:34:12 AMCompleted: Oct 27, 2025, 10:35:52 AMpubliccompleted
Loading additional data...

Summary

This website contacted 69 IPs in 2 countries across 21 domains to perform 89 HTTP transactions. The main domain is preview.webflow.com.

Submitted URL: https://preview.webflow.com/preview/bt-ee-ce5353?utm_medium=preview_link&utm_source=designer&utm_content=bt-ee-ce5353&preview=9ae71b9e3763eb9b426eb7206bcf0ff0&workflow=preview

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

High‑risk phishing page impersonating BT on an unranked preview domain.

Risk Factors
Brand impersonation on a non‑official, unranked domain
Presence of a suspicious external domain (ipstack.com) flagged as malicious
Unranked domain used for brand‑specific content
Domain age information unavailable

Details

Page Title

Webflow - BT EE

Scan Type

public

Language

🇺🇸

English

(56% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'preview.webflow.com' uses the commercial generic top-level domain (.com) and includes subdomain 'preview'. The core label 'webflow' covers 7 characters with two vowels and 5 consonants. Word splitting yields 2 words: web, flow. Median word length is 3.5 characters. The linguistic tilt is Chinese (Pinyin) for 'web'. It also appears in English and Vietnamese contexts.

Screenshot

Security scan screenshot of https://preview.webflow.com/preview/bt-ee-ce5353?utm_medium=preview_link&utm_source=designer&utm_content=bt-ee-ce5353&preview=9ae71b9e3763eb9b426eb7206bcf0ff0&workflow=preview

Page Load Overview

58.89s
Total Load Time
89
HTTP Requests
21
Domains
13.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:56%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:56%
Script Type:Latin
Text Length:194 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
21142.250.185.74United States
AS15169GOOGLE
118.66.147.127United States
AS16509AMAZON-02
1108.138.26.4United States
AS16509AMAZON-02
118.173.205.118United States
AS16509AMAZON-02
1104.18.7.168United States
AS13335CLOUDFLARENET
1172.217.18.10United States
AS15169GOOGLE
154.91.241.83Ashburn, Virginia, United States
AS14618AMAZON-AES
152.88.33.160Boardman, Oregon, United States
AS16509AMAZON-02
1104.18.2.70United States
AS13335CLOUDFLARENET
1104.18.10.212United States
AS13335CLOUDFLARENET
8969--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C7A4D5A4F0F3953A413F7072E19A2B4A63A7D30B57CE3FF2700DA0A06B59A5D1D27658

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:bNDtB+9V9zwv4pRf9/2xXupNU1wqL1lBOGDll:hL+9fU1wqL1lBOGDll

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:461651:IM4sLHIkGMkgCp0IgjWsqcQIBlAIAwWDh6OOAAHwCZjSiCoIqYG4COAiGaKDABMMoS0RKjJAR0CcWAhgQDCQUxUqAQTrSMWN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000001818000000
Perceptual Hash:9966669999666699
Difference Hash:0000001010000000
Wavelet Hash:0c0c343c3c3c0c0c
Color Hash:#2d4386

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data