Security Scan Report: winsbonuss.netlify.app

Redirected to:
https://winsbonuss.netlify.app/
Submitted: Aug 21, 2026, 12:45:04 AMCompleted: Aug 21, 2026, 12:46:25 AMpubliccompleted

This website contacted 2 IPs in 2 countries across 11 domains to perform 9 HTTP transactions. The main domain is winsbonuss.netlify.app and was registered 8 years ago.

Submitted URL: http://winsbonuss.netlify.app/

Effective URL:

https://winsbonuss.netlify.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Page impersonates OpenSea, hosts malicious JS with C2, and is flagged as a wallet‑drainer; treat as confirmed scam.

Risk Factors (5)
Primary domain IoC (wallet drainer)
Malicious JavaScript with C2/WebSocket backdoor
Critical IDS malware alerts
Brand impersonation of OpenSea on a Netlify subdomain
Connection to blockchain RPC endpoints for unauthorized wallet approvals
Domain age information unavailable

Details

Page Title

OpenSea.io

Scan Type

public

Domain Name Analysis

Domain 'winsbonuss.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'winsbonuss'. The core label 'netlify' covers 7 characters with 2 vowels and 5 consonants. Segmentation suggests 3 words: net, li, fy. Median word length is 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://winsbonuss.netlify.app/

Page Load Overview

5.77s
Total Load Time
5.5 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:27 chars
Detector Agreement:100%
Language mismatch: Declared as en-US but detected as es

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.67United States
AS16509Amazon.com, Inc.
463.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
92--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D6B42367E193AD2B6959154F62970F691E2010CDF4F4BB8E9FC46CEAA00FE91CD1281F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:xGEHiotMLFwPI/Y9wPRM4iuRd145n/on9Spfj3J:xGExQA98M8Rz45/Pd5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:500021:gKCiRxgGAKhRIaskodUQAhzPQAFYIzuSoYEBIBjJr4AFgAJisKFQ3EZPImAIuQ4QAoEACMgiVQFFRI4QCARyI0AaXWApARQI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff000f0f0f07efff
Perceptual Hash:b12ac47dc8c99bca
Difference Hash:b61c59db5a1e2e80
Wavelet Hash:ff000d0f0f0307ff
Color Hash:#e06cc1

Scan History

Scan history not available

Unable to load historical scan data