Security Scan Report: moonlit-phoenix-8039b7.netlify.app

Redirected to:
https://moonlit-phoenix-8039b7.netlify.app/
Submitted: Aug 29, 2026, 3:50:42 AMCompleted: Aug 29, 2026, 3:51:49 AMpubliccompleted

This website contacted 2 IPs in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is moonlit-phoenix-8039b7.netlify.app and was registered 8 years ago.

Submitted URL: http://moonlit-phoenix-8039b7.netlify.app/

Effective URL:

https://moonlit-phoenix-8039b7.netlify.app/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Page impersonates Google login, collects credentials, and is flagged by Safe Browsing – treat as high‑risk phishing.

Risk Factors
Brand impersonation of Google on an unranked domain
Credential collection form (email + password)
Google Safe Browsing social engineering warning
Unknown subdomain creation date (potentially brand‑new)
Cross‑origin POST requests (potential exfiltration path)
Domain age information unavailable

Details

Page Title

Sign in - Google Accounts

Scan Type

public

Domain Name Analysis

The domain 'moonlit-phoenix-8039b7.netlify.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'moonlit-phoenix-8039b7'. The core label 'netlify' covers 7 characters split between two vowels and 5 consonants. Segmentation suggests three words: net, li, fy. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://moonlit-phoenix-8039b7.netlify.app/

Page Load Overview

0.21s
Total Load Time
6 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:223 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software38% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
235.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
32--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BB3209A3356024207467C2B87B97E34A36239403C9068A2479EC425EDF8EFE55EB76DD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:PABI7ThN4KRsqNmR4+F7OFFM5Mnx4AZRgXvOnxYDzT1B6Sf+Vqq27l:PABIhWKWqe4K7OFFtnx3Lg2A/cVqVB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11993:IfQmSEI48AUAhFKBIKBCL6EGHQQoIDNQSwjQByATGCTAoRgwRgIADhSAskUcBhK3MJiRACiFYULISYCUcrMKBBKgAgFBgQ6C

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fe7e7e3e3ffff7e
Perceptual Hash:a623998d4ccd999b
Difference Hash:800c080404000080
Wavelet Hash:27a70707070fcf4e
Color Hash:#532d86

Other Hashes

Crop Resistant:800c080404000080

Scan History

Scan history not available

Unable to load historical scan data