Security Scan Report: 3d08-4010-aa2d-88ca661975d1-12b085.netlify.app

Redirected to:
https://3d08-4010-aa2d-88ca661975d1-12b085.netlify.app/sdd/wp_content/...
Site favicon
Submitted: Aug 26, 2026, 1:45:20 AMCompleted: Aug 26, 2026, 1:47:49 AMpubliccompleted

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 2 HTTP transactions. The main domain is 3d08-4010-aa2d-88ca661975d1-12b085.netlify.app and was registered 8 years ago.

Submitted URL: http://3d08-4010-aa2d-88ca661975d1-12b085.netlify.app/sdd/wp_content/media/css/zm/zm.html/

Effective URL: https://3d08-4010-aa2d-88ca661975d1-12b085.netlify.app/sdd/wp_content/media/css/zm/zmRedirected

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

The site impersonates Zimbra and harvests login credentials on an unknown‑age Netlify subdomain, indicating a high‑risk phishing page.

Risk Factors
Brand impersonation (Zimbra) on a non‑official domain
Credential collection form (email/password)
Unknown subdomain age on shared hosting platform
Unranked / low‑reputation domain
Domain age information unavailable

Details

Page Title

Zimbra Web Client Sign In

Scan Type

public

Language

🇺🇸

English

(42% confidence)

Category

forum community discussion

(81%)

Domain Information

You're looking at domain '3d08-4010-aa2d-88ca661975d1-12b085.netlify.app' on the application-focused generic top-level domain (.app), featuring subdomain '3d08-4010-aa2d-88ca661975d1-12b085'. The second-level label 'netlify' is 7 characters long containing two vowels alongside 5 consonants. Splitting it apart reveals three words: net, li, fy. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of 3d08-4010-aa2d-88ca661975d1-12b085.netlify.app

Page Load Overview

3.02s
Total Load Time
6
HTTP Requests
1
Domains
15 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:42%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:42%
Script Type:Latin
Text Length:919 chars
Detector Agreement:67%

Website Classification

Primary Category

forum community discussion81% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

forum community discussion
81%
technology software
39%
social media network
37%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
635.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
61--

Page Statistics

6
Requests
1
Unique Domains
18.3 KB
Total Size

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18C712F0028F18C72925249D06DD1BE162DE882238307584CBD9D9FFE5FE3D8A832B369

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:81m0oHdPZLOo1A2eXHKsbw2NfLAmjJGQY+Mspbpb:fLpde3KYfLAmFGFAtb

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3805:AAAABgAQKFAABEIIABAAAkFggGAGBJgRAS4PEACNAEJoNRQQ4wioCIABQUABBCAAGAxgIoEYeAAAAAwBIFAgAECAAQAgAASA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7c3c3e7ffffe7
Perceptual Hash:b3a2cccc33339966
Difference Hash:224d4d4d4d32040c
Wavelet Hash:ffe7e7c3c3270000
Color Hash:#40aebf

Scan History

Scan history not available

Unable to load historical scan data