Security Scan Report: forms.gle

Redirected to:
https://docs.google.com/forms/d/e/1FAIpQLSdDeoEpG7QbcEkvJUubUHONmangvT...
Submitted: Oct 25, 2025, 3:58:52 PMCompleted: Oct 25, 2025, 4:01:36 PMpubliccompleted
Loading additional data...

Summary

This website contacted 26 IPs in 2 countries across 8 domains to perform 23 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/ob8JybgcKDdp9awg7

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSdDeoEpG7QbcEkvJUubUHONmangvTW91hHDrPcTwC80QFgoGw/viewform?usp=send_formRedirected

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Impersonates Netflix on Google Forms – high‑risk phishing page.

Risk Factors
Brand impersonation: Netflix branding on a non‑Netflix domain
Use of a legitimate service (Google Forms) to create a deceptive brand‑specific form
Domain age information unavailable

Details

Page Title

Netflix Cancellation

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'forms.gle' uses the .gle top-level domain. Its registrable label 'forms' stretches across 5 characters with one vowel and 4 consonants. Tokenizing the label suggests 1 word: forms. Median word length is 5 characters. Most frequently, 'forms' shows up in English. You may catch it in Chinese (Pinyin) and Tamil as well. Net impression: English phrase with single-word simplicity.

Screenshot

Security scan screenshot of https://forms.gle/ob8JybgcKDdp9awg7

Page Load Overview

3.15s
Total Load Time
23
HTTP Requests
8
Domains
771 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:801 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7142.250.185.163United States
AS15169GOOGLE
4142.250.186.35United States
AS15169GOOGLE
4142.250.185.78United States
AS15169GOOGLE
3142.250.185.138United States
AS15169GOOGLE
2172.217.18.3United States
AS15169GOOGLE
1142.250.185.206United States
AS15169GOOGLE
1142.250.185.129United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
0142.251.140.174United States
AS15169GOOGLE
0142.250.185.142United States
AS15169GOOGLE
2326--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AB53B54712200CBEEE5755F29591AF5E3F6D123BB007107DF2FC5FA23B8AA9940152BA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:+ngL/P/djiWopmuO3Fb5Vk3Q0twuNXgCe+BKYjR0S8pkJIssS+WZ:z/5iXU3FbF0twj/+hjeHssS+WZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:61435:CS0RUQUBTK5ASFggWwE1eADAAnAGcBAhiBmMl4aQGUDA9BkYwAAFQSyBmBdBqlYPUiBJikQAgRIaJqIKgopcydC4RraCanAM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data