Security Scan Report: heroic-daffodil-432a9c.netlify.app

Site favicon
Submitted: Sep 12, 2026, 6:13:40 PMCompleted: Sep 12, 2026, 6:14:00 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

French-language credential phishing page on a free Netlify subdomain: collects email mailbox credentials via a disguised password field with Unicode evasion. Do not enter any credentials.

Risk Factors
Disguised password field (text type with password placeholder) — evasion technique
Unicode confusion/evasion in form fields
Login form harvesting mailbox credentials on an instant/unknown-age hosting-platform subdomain
Deceptive page title vs. actual content mismatch
Unranked domain with no reputation supporting a credential-collection page
Domain age information unavailable

Details

Page Title

Facture

Scan Type

public

Domain Name Analysis

You're looking at domain 'heroic-daffodil-432a9c.netlify.app' on the application-focused generic top-level domain (.app) and includes subdomain 'heroic-daffodil-432a9c'. The core label 'netlify' covers 7 characters containing 2 vowels alongside five consonants. Segmentation suggests three words: net, li, fy. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://heroic-daffodil-432a9c.netlify.app

Page Load Overview

1.81s
Total Load Time
679 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:194 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as fr

Website Classification

Primary Category

finance banking83% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
83%
government public service
61%
adult content
54%
news media journalism
39%
corporate business
38%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5199.36.158.100United States
AS54113Fastly, Inc.
135.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
1192.178.183.94Google · CDNUnited States
AS15169Google LLC
1188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.127.95Google · CDNUnited States
AS15169Google LLC
1195.154.239.26Paris, Île-de-France, France
AS12876Scaleway SAS
163.176.8.218Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
117--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D61E62202A46A5101A2D0B237D5B246F906D21FAF02E5B0B1DD03BA6FCEEE250F57D1

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TPcTGhOGEaeC/hYyy2SOnP+dZNrcQ7a01p97Cwr7XooZ7kI28XZ/22pk:T0TG1BZd1Yc2x7CMz72quwk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3459:SACQIAAIiYCAgQgBAAJAKBABgA0IRAAMAAAAgDQgACUAABACAKAIQBRAQQAEEAwAAgIQg1FBCBAAAgECAAIBAQkBBgAMkFAg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003c7eb602fffffe
Perceptual Hash:d703d02c7daaf829
Difference Hash:d6cccc6e6664664a
Wavelet Hash:003c7e2200b6fffe
Color Hash:#1f9353

Scan History

Scan history not available

Unable to load historical scan data