Security Scan Report: preview.webflow.com

Site favicon
Submitted: Oct 14, 2025, 6:45:48 PMCompleted: Oct 14, 2025, 6:46:59 PMpubliccompleted
Loading additional data...

Summary

This website contacted 43 IPs in 2 countries across 15 domains to perform 61 HTTP transactions. The main domain is preview.webflow.com.

Submitted URL: https://preview.webflow.com/preview/bt-b-site?utm_medium=preview_link&utm_source=designer&utm_content=bt-b-site&preview=86e3191134978beef7175337fc21e25c&workflow=preview

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

High‑risk phishing page due to BT brand impersonation and a malicious external link.

Risk Factors
Brand impersonation on an unranked domain
Presence of a malicious Indicators of Compromise (ipstack.com) external link
Unranked/low‑reputation hosting domain
Domain age information unavailable

Details

Page Title

Webflow - BT B Site

Scan Type

public

Language

🏳️

UNKNOWN

(0% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'preview.webflow.com' on the commercial generic top-level domain (.com); it also runs on subdomain 'preview'. The second-level label 'webflow' is 7 characters long with 2 vowels and five consonants. Tokenizing the label suggests two words: web, flow. Median word length comes out to 3.5 characters. 'web' most strongly signals Chinese (Pinyin). Secondary signals appear in English and Vietnamese.

Screenshot

Security scan screenshot of https://preview.webflow.com/preview/bt-b-site?utm_medium=preview_link&utm_source=designer&utm_content=bt-b-site&preview=86e3191134978beef7175337fc21e25c&workflow=preview

Page Load Overview

37.84s
Total Load Time
61
HTTP Requests
15
Domains
10.0 MB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Language Code:unknown
Detection Confidence:0%
Text Length:19 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
19108.138.26.93United States
AS16509AMAZON-02
1108.138.26.4United States
AS16509AMAZON-02
1104.18.2.70United States
AS13335CLOUDFLARENET
118.66.147.127United States
AS16509AMAZON-02
118.66.147.94United States
AS16509AMAZON-02
154.167.161.29Ashburn, Virginia, United States
AS14618AMAZON-AES
113.226.247.129United States
AS16509AMAZON-02
1108.138.26.97United States
AS16509AMAZON-02
1172.64.153.109United States
AS13335CLOUDFLARENET
1142.250.185.138United States
AS15169GOOGLE
6143--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1146475A8F1F3963A417E7072D19A2B46A7A3C30B63DE7FF3600CA4906B1995D0D1769C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:KvxzDtRj7y99Q47GKb5ZU1wqL1lBOGDlxCc:KNDtB+9NU1wqL1lBOGDlj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:311105:oQBRAkrWAmAoiKOIMhIFNQhFIUFABFZzFLpRDQEwCEKAlgBAjBWNaAIargAjeQEQAGESCWQoM0oAoEacrESBUhAzAGWgHmgQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000001818000000
Perceptual Hash:cc3333cccc3333cc
Difference Hash:0000003030000000
Wavelet Hash:0000243c38300000
Color Hash:#6ce081

Other Hashes

Crop Resistant:0000003030000000

Scan History

Scan history not available

Unable to load historical scan data