Is effortless-puffpuff-a0722c.netlify.app safe?
http://effortless-puffpuff-a0722c.netlify.app/
Coveragestrong2 of 4 applicable core capabilities
Netlify-hosted page impersonates Bank of China (Hong Kong) to run a fake loan assessment.
The site displays the BOCHK logo and the name 'GreenFlow 綠貸通' but is served from a Netlify subdomain, not an official bank domain. Five antivirus engines flag it as phishing, and the only visible call-to-action is a button labeled '開始智能綠色評估' that starts a simulated loan process.
Loading saved screenshot
Preparing the saved page preview.
Where this site sits
- Dangerous1–20
- High Risk21–44
- Moderate Risk45–69
- Low Risk70–84
- Safe85–100
The score combines saved evidence strength and analysis quality. Coverage is reported separately.
01 · Investigation Brief
Investigation Brief
The site displays the BOCHK logo and the name 'GreenFlow 綠貸通' but is served from a Netlify subdomain, not an official bank domain. Five antivirus engines flag it as phishing, and the only visible call-to-action is a button labeled '開始智能綠色評估' that starts a simulated loan process.
Antivirus detections and hosting mismatch
Five independent antivirus families (Emsisoft, ESET, Fortinet, Netcraft, Webroot) classify the page as malicious or phishing.
The page is hosted on effortless-puffpuff-a0722c.netlify.app, a Netlify subdomain, while the branding claims to be Bank of China (Hong Kong).
What a visitor sees and does
The landing page shows the BOCHK logo and the heading 'GreenFlow 綠貸通|BOCHK SME Green Finance'.
Clicking the prominent '開始智能綠色評估' button is the only commercial CTA; the page gives no further information about where the data goes.
Why the score is 15
5 independent antivirus families reported an adverse result. This comes from a saved antivirus observation rather than a new submission, so treat the detection as real but confirm the timing. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
5/ 92
detectionsSaved result - stale
5 engines flagged this URL
Every saved adverse engine is listed below. The full provider matrix remains available for audit.
- Malicious
- 5
- Suspicious
- 0
- Total
- 92
| Engine | Finding |
|---|---|
| EmsisoftMalicious | phishing |
| ESETMalicious | phishing |
| FortinetMalicious | phishing |
| NetcraftMalicious | malicious |
| WebrootMalicious | malicious |
All 92 engine results
- Emsisoft - phishing - Malicious
- ESET - phishing - Malicious
- Fortinet - phishing - Malicious
- Netcraft - malicious - Malicious
- Webroot - malicious - Malicious
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- alphaMountain.ai - unrated - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- BitDefender - clean - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- ChainPatrol - clean - Clean
- Chong Lua Dao - clean - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- CRDF - clean - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- CyRadar - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Ermes - unrated - Clean
- ESTsecurity - clean - Clean
- Forcepoint ThreatSeeker - clean - Clean
- Fortra - unrated - Clean
- G-Data - clean - Clean
- GCP Abuse Intelligence - unrated - Clean
- Google Safe Browsing - clean - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Gridinsoft - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Kaspersky - clean - Clean
- LevelBlue - clean - Clean
- Lionic - clean - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- OpenPhish - clean - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- Rising - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- SOCRadar - unrated - Clean
- Sophos - clean - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- VIPRE - unrated - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Xcitium Verdict Cloud - clean - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
What we observed
Loading saved screenshot
Preparing the saved page preview.
Visual context from the captured page
Bank of China (Hong Kong) logo GreenFlow 綠貸通|BOCHK SME Green Finance
What the captured page showed
2 observations- 01
Bank of China (Hong Kong) logo
- 02
GreenFlow 綠貸通|BOCHK SME Green Finance
03 · Investigation Story
Investigation story
What the site claims
GreenFlow 綠貸通|BOCHK SME Green Finance
What we observed
The page content was captured and checked alongside 92 antivirus results.
What independent research found
The search completed without a material external warning or corroborating report.
What remains unverified
2 of the 4 applicable core capabilities did not complete, so those gaps remain visible in the coverage ledger.
What kind of site and risk is this?
Threat category
Phishing & Impersonation
Service and business model
Login Portal
Observed behavior
Evidence behind this classification
- 015 independent antivirus families reported an adverse result. This comes from a saved antivirus observation rather than a new submission, so treat the detection as real but confirm the timing.
- 02Site uses a Netlify subdomain while displaying Bank of China (Hong Kong) branding.
- 03text GreenFlow 綠貸通|BOCHK SME Green Finance effortless-puffpuff-a0722c.netlify.app
Web research findings
Independent findings for effortless-puffpuff-a0722c.netlify.app, including public complaints, named review sources, registration records, and look-alike-domain evidence. A missing result is shown as unverified, never converted into a clean bill of health.
No independently sourced scam reports or credibility records were found for effortless-puffpuff-a0722c.netlify.app. That is common for new or low-traffic sites and does not clear the site.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
- Domaineffortless-puffpuff-a0722c.netlify.app
- Redirects toeffortless-puffpuff-a0722c.netlify.app
- Hosted byAmazon Data Services Northern Virginia
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No direct contact email found on the captured page.
Domain & Encryption
Redirect Chain
- 1301http://effortless-puffpuff-a0722c.netlify.app/
- 2206https://effortless-puffpuff-a0722c.netlify.app/
Server Reputation
05 · Evidence Ledger
Evidence ledger
- Antiviruspartial
- Browser threat feedcomplete
- Page contentpartial
- Analysiscomplete
- Visual evidencecomplete
The conclusion is supported by the evidence saved with this report.
Technical threat
suspiciousMalware, phishing, credential theft and hostile infrastructure.
Additional evidence review · Additional evidence review
Operator / customer risk
unknownComplaints, withdrawals, business conduct and commercial traps.
No confirmed evidence in this dimension.
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding | Freshness |
|---|---|---|---|---|
| Antivirus | 5 of 92 engines flagged | Limited | Adverse | stale fallback · Sep 1, 2026 |
| Browser protection | No browser threat-list match | Completed | No adverse finding | Not available |
| Page content | Page fetched · HTTP 200 | Limited | No saved finding | Not available |
| Visual evidence | 2 visible observations saved with the page capture | Completed | No adverse finding | Not available |
| Independent research | The search completed without a material external finding | Completed | No adverse finding | Not available |
- Antivirus
- Result5 of 92 engines flagged
- CompletionLimited
- FindingAdverse
- Freshnessstale fallback · Sep 1, 2026
- Browser protection
- ResultNo browser threat-list match
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Page content
- ResultPage fetched · HTTP 200
- CompletionLimited
- FindingNo saved finding
- FreshnessNot available
- Visual evidence
- Result2 visible observations saved with the page capture
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Independent research
- ResultThe search completed without a material external finding
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
07 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
Is effortless-puffpuff-a0722c.netlify.app a scam or a legit website?
Is effortless-puffpuff-a0722c.netlify.app safe to use?
What should I do if I already gave my details to effortless-puffpuff-a0722c.netlify.app?
Can I get my money back from effortless-puffpuff-a0722c.netlify.app?
Did effortless-puffpuff-a0722c.netlify.app steal my password or personal information?
How do I report effortless-puffpuff-a0722c.netlify.app?
Why does effortless-puffpuff-a0722c.netlify.app look legitimate if it's a scam?
Has effortless-puffpuff-a0722c.netlify.app been flagged by antivirus engines?
Is effortless-puffpuff-a0722c.netlify.app on any phishing or malware blacklists?
How old is the effortless-puffpuff-a0722c.netlify.app domain?
Where is effortless-puffpuff-a0722c.netlify.app hosted?
How often is the effortless-puffpuff-a0722c.netlify.app report updated?
08 · Final Verdict
Final verdict
Netlify-hosted page impersonates Bank of China (Hong Kong) to run a fake loan assessment.
The site displays the BOCHK logo and the name 'GreenFlow 綠貸通' but is served from a Netlify subdomain, not an official bank domain. Five antivirus engines flag it as phishing, and the only visible call-to-action is a button labeled '開始智能綠色評估' that starts a simulated loan process.
09 · Community
