Security Scan Report: php-web-server--unitmexi.replit.app

Submitted: Sep 16, 2026, 7:50:11 AMCompleted: Sep 16, 2026, 7:50:42 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

7
Risk Score

Fake WhatsApp verification page on a free Replit subdomain harvesting phone numbers, flagged by Google Safe Browsing for social engineering and by threat intel for phishing.

Risk Factors
Google Safe Browsing Social Engineering conviction
Phishing threat-intel match on the primary domain
Phone-number / one-time-code collection form on a spoofed brand page
Deceptive hostname on an anonymous free-hosting subdomain
Page presents itself as a brand it does not own
Domain age information unavailable

Details

Page Title

Validación

Scan Type

public

Domain Name Analysis

The domain name 'php-web-server--unitmexi.replit.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'php-web-server--unitmexi'. The second-level label 'replit' is 6 characters long with two vowels and 4 consonants. Splitting it apart reveals 2 words: rep, lit. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://php-web-server--unitmexi.replit.app/index1.html

Page Load Overview

8.30s
Total Load Time
561 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:365 chars
Detector Agreement:100%

Website Classification

Primary Category

gambling betting66% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

gambling betting
66%
social media network
62%
technology software
49%
cryptocurrency blockchain
41%
finance banking
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
335.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
234.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.13.95Google · CDNUnited States
AS15169Google LLC
2104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.110.94Google · CDNUnited States
AS15169Google LLC
157--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T116517A0054F0CCB242EB1CCD56A27C2A9AF9831792124748F67E4BFA0FB6E5ED133415

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:s85wZOeDG0l6wIq8GDPZmYHO+WbkGkKA/d1ND:75wZOcG0l6wIqSEhKP6PD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2958:AgBEAAgABACEkABhSJAYIYAABwAEBAAISAAEAQBiAACNEAAEDEZARAABIACIAAACIHgABAkABkRAgAAQgkIECAABAqAgEUAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:d9897622dd89cd23
Difference Hash:030cb2b2b2b33148
Wavelet Hash:43177b183d1d8d78
Color Hash:#e0ad6c

Other Hashes

Crop Resistant:030cb2b2b2b33148

Scan History

Scan history not available

Unable to load historical scan data