Security Scan Report: roaring-marzipan-8ace7d.netlify.app

Submitted: Sep 15, 2026, 12:45:13 AMCompleted: Sep 15, 2026, 12:45:34 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake Steam login page on a throwaway Netlify subdomain harvesting Steam account names, passwords and Steam Guard 2FA codes — do not enter credentials; this is credential phishing impersonating Valve's Steam.

Risk Factors (5)
Brand impersonation of Steam (Valve) on a domain that is not steampowered.com or any Valve property
Credential and 2FA-code harvesting forms presented as the Steam login flow
Hosted on an instantly-provisioned free Netlify subdomain with an unattributable creation date
External POST beacon to api.ipify.org to fingerprint visitors (likely victim-IP logging for the operator)
Fake error text ('Nieprawidłowa nazwa konta lub hasło') used to prompt repeated credential re-entry
Domain age information unavailable

Details

Page Title

Zaloguj się - Steam

Scan Type

public

Domain Name Analysis

The domain name 'roaring-marzipan-8ace7d.netlify.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'roaring-marzipan-8ace7d'. The registrable portion 'netlify' spans 7 characters with two vowels and 5 consonants. Segmentation suggests three words: net, li, fy. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://roaring-marzipan-8ace7d.netlify.app/

Page Load Overview

2.67s
Total Load Time
18 KB
Total Size

Language Analysis

Primary Language

🇵🇱Polish
Code: pl
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pl
Text Length:635 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network90% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
90%
corporate business
79%
technology software
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2146.75.123.52Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
12.16.168.8Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
43--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T193521A7164F5203E7127C4A4B6E36A473986C407C58B9A64FCAD67A48FCF9961332B8C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:sxmSpwclMMFJnbY9AFeUtd3T6u8bcoc5hbYpYHr99CVNSeKLBJrpgClRMwj:6XpwcnvGAFeUtd3T6f0b2YHr99CIJ+S

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:13292:t4gCCjKcLSNAB2gKAwIFIhigEejEMuTBJAhG9ImEsAIRIEkQTaYogADhp24BkRinixSguylAR2wRDZlkOFpEqA6UlAQGAkQg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:04ffc3e3ffffff00
Perceptual Hash:9cb6369c1c36369c
Difference Hash:6c021404b2320810
Wavelet Hash:04ffc0c0dbc3ff00
Color Hash:#54ac53

Other Hashes

Crop Resistant:6c021404b2320810

Scan History

Scan history not available

Unable to load historical scan data