Scan report · 16 days agoPublic

drive.google.com

216.58.201.174AS15169 · US

the page title spells Еstееmеd, Mеmbеr, Yоu with Latin letters and Cyrillic or Greek look-alikes inside the same word, so it reads normally to a person while matching nothing a keyword filter looks for. Substituted letters are a way of getting a message past text screening, and they have no other use

Verdict

Be careful — warning signs found

Automated

This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingThe title is spelled in two alphabets at once
Еstееmеd, Mеmbеr, Yоu, Hаvе (+4 more)

Words in this page's title are written with Latin letters and Cyrillic or Greek look-alikes inside the same word — for example a Cyrillic о (U+043E) standing in for the Latin o, or е (U+0435) for e. The word reads normally to a person and matches nothing that screens text for keywords. A page whose title is built that way is being written to get past filters, and a document or brand name written this way is not a typography choice.

Analyst noteCopy the word above and look at its codepoints: the substituted letters are outside the Latin range. Note also where the title came from — a file-sharing viewer puts the UPLOADED FILE'S NAME in the title, so a substitution there was chosen by whoever uploaded the file, not by the hosting provider. A page in Russian or Greek is not this: it writes whole words in one alphabet.

InfoCross-domain scripts injected at runtime
14 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
216.58.201.174GOOGLE - Google LLC, US · AS15169US
TLS
CN=WR2, O=Google Trust Services, C=US · expires Nov 27, 2026

WHOIS

Registrar
MarkMonitor Inc.
Created
Sep 15, 1997
Expires
Sep 14, 2028
Nameservers
ns1.google.comns2.google.comns3.google.comns4.google.com
28 malicious25 suspicious

Hashes & fingerprints

Page capture

Live

Title “[Еstееmеd Mеmbеr] -> Yоu Hаvе аn Оvеrduе! Pаy Nоw! - Google Drive”

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
[Еstееmеd Mеmbеr] -> Yоu Hаvе аn Оvеrduе! Pаy Nоw! - Google Drive
Load
10.77 s · 62 requests
Stack · 4HTTP/3Open GraphOpenGSEJava