Security Scan Report: velvety-sable-2820f6.netlify.app

Site favicon
Submitted: Sep 26, 2026, 1:50:29 PMCompleted: Sep 26, 2026, 1:52:26 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 65%

7
Risk Score

Bare Korean login/password page on a throwaway Netlify subdomain with no branding or content, flagged by phishing heuristics. No confirmed IoC or exfiltration, but it shows the shape of a credential-harvesting landing page.

Risk Factors (5)
Login/credential form (email + password) hosted on a free shared hosting platform with an unknown-age, auto-generated subdomain
No site identity, branding, navigation or legitimate content behind the login prompt — bare credential-collection page
IDS heuristics flag the Netlify-hosted request pattern as a possible phishing landing
Dynamic code generation via Function() constructor
No domain reputation (not in Cisco Umbrella top 1M)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'velvety-sable-2820f6.netlify.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'velvety-sable-2820f6'. The second-level label 'netlify' is 7 characters long containing two vowels alongside 5 consonants. Tokenizing the label suggests 3 words: net, li, fy. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://velvety-sable-2820f6.netlify.app/

Page Load Overview

3.92s
Total Load Time
325 KB
Total Size

Language Analysis

Primary Language

🇰🇷Korean
Code: ko
Confidence:60%
Script:Hangul
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:68 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ko

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1063.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
0142.251.13.95Google · CDNUnited States
AS15169Google LLC
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0143.204.181.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0172.217.114.4Google · CDNUnited States
AS15169Google LLC
0208.91.114.103Langley, British Columbia, Canada
AS40934Fortinet Inc.
035.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
0143.204.181.67Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1011--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11342A36385A309196407D0A8AFDBA70637A5C063C10BCD583F9CA79ECFC5ED588A738C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:2LlFoY1ALsbtDc5ckOIFl+d9Vfq7zONWziRZBgtcXj:2LlFYLaAuIF0Vy7gVZBJj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12210:BwAAxKISkZBgggIQn2FDjhAEAiIlDLcXMKARAIBIbUKSYlcRSNaUBACGA/AIIUBAgk71oViEAociAIlFBQYAoEQpITzHhxwh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00183c1800000000
Perceptual Hash:99996666339999cc
Difference Hash:4cb2b2b20c300000
Wavelet Hash:303c3c3cf0f0f0f0
Color Hash:#79d2c2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data