Security Scan Report: security-server-landing-page--ginola080.replit.app

Submitted: Sep 27, 2026, 9:50:13 AMCompleted: Sep 27, 2026, 9:50:53 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake 'example.com Mail Authentication' portal on a free replit.app subdomain harvesting email/password via a deceptive login form, backed by IP-lookup JS and fake error prompts. Credential phishing — do not enter any data.

Risk Factors (5)
Credential-capturing password form on a shared/instant-publish hosting namespace
Brand impersonation of example.com on a non-example.com domain
Cross-origin IP-lookup requests (ipapi.co, api.ipify.org) typical of phishing kits
Deceptive hostname 'security-server-landing-page--ginola080' unrelated to the claimed portal
Fake 'authentication error' retry flow designed to re-prompt for credentials
Domain age information unavailable

Details

Page Title

PORTAL - example.com Mail Authentication

Scan Type

public

Domain Name Analysis

You're looking at domain 'security-server-landing-page--ginola080.replit.app' on the application-focused generic top-level domain (.app); it also runs on subdomain 'security-server-landing-page--ginola080'. Count 6 characters in 'replit' with two vowels and 4 consonants. Splitting it apart reveals 2 words: rep, lit. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://security-server-landing-page--ginola080.replit.app/

Page Load Overview

5.69s
Total Load Time
354 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:400 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software75% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
75%
government public service
33%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
334.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
135.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
152.72.208.91Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1142.251.153.119Google · CDNUnited States
AS15169Google LLC
1142.250.154.147Google · CDNUnited States
AS15169Google LLC
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.155.119Google · CDNUnited States
AS15169Google LLC
1192.178.183.105Google · CDNUnited States
AS15169Google LLC
1210--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B5A2D7564AF30415B523E1783FFB530C3A7180079645C968B95C5394DFC8CA266BFBE9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:9BIBfVKDZ6rXIsWsfll9D+X/2rsiQf2O0k:92BfVOAr4sfN/mWsi9k

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21824:EAAqCSiCkQiBAmaCgEQADQYqBkHIViJTjgyUgWBQ6GQQWHAoSeSh4COVuQGpoasINAQAGAgKITIAVBJQJSERAgXkBACBgBoI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000001818000000
Perceptual Hash:9c3876a3c98b6723
Difference Hash:10322eb2b20c0100
Wavelet Hash:3f0181ff1c040f0e
Color Hash:#bfd279

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data