Security Scan Report: waitingpackageco.firebaseapp.com

Submitted: Oct 3, 2026, 11:53:13 AMCompleted: Oct 3, 2026, 11:53:49 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Bare 'confirm you are human' gate with a broken reCAPTCHA on a free Firebase subdomain of unknown age. No forms, impersonation or threat-intel hits, so no confirmed phishing — but the pattern warrants caution.

Risk Factors (5)
Human-verification interstitial ('confirm you are human') on free user-generated hosting is a common gateway shape used ahead of phishing redirects
Broken reCAPTCHA configuration ('Invalid site key') indicates an unmaintained or copied gate page
No site identity, no real content, no contact or ownership information
Actual subdomain creation date unknown — could have been deployed minutes before the scan
Unranked in Cisco Umbrella with no reputation history
Safety Factors (4)
Zero forms on the page: no password, credential or payment fields detected
No cross-origin credential exfiltration or suspicious JavaScript behavior observed
No Indicators of Compromise, YARA malware matches, IDS alerts or kit-roster hits
Third-party scripts are served from popular, well-known domains (gstatic.com, google.com)
Domain age information unavailable

Details

Page Title

Verification

Scan Type

public

Domain Name Analysis

The domain name 'waitingpackageco.firebaseapp.com' uses the commercial generic top-level domain (.com) with subdomain 'waitingpackageco'. The second-level label 'firebaseapp' is 11 characters long holding five vowels versus 6 consonants. Word splitting yields three words: fire, base, app. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://waitingpackageco.firebaseapp.com/

Page Load Overview

0.92s
Total Load Time
798 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:76 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical57% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
57%
news media journalism
41%
government public service
40%
adult content
27%
finance banking
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1142.251.157.119Google · CDNUnited States
AS15169Google LLC
1142.251.127.94Google · CDNUnited States
AS15169Google LLC
1142.251.153.119Google · CDNUnited States
AS15169Google LLC
1142.251.156.119Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
96--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18051C7B7659054255D13827198F1B6C97422C20BF9C0E1E1BCE866B8BFC1D73C447569

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TXJ+CKzrlfr9m7QpZcqgjKX8C7BmYYdshOj0xm3OZa7NG4hYy11rZjnOzV:TkpzrprwQLwf4OYa7I4OynlOp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3127:JABAoAAgIAUMCBBABAAACAAAAMBAAQQYAIoAwAAAAQAAAQQAFCECAIAAEBgSlIgBADAAyIUAAgoAgEAhQEAKABCAoAgCgAAB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:080c180000000000
Perceptual Hash:999933666ccccccc
Difference Hash:105a320000000000
Wavelet Hash:d8c8d8c0f0f0f0f0
Color Hash:#7940bf

Other Hashes

Crop Resistant:105a320000000000

Scan History

Scan history not available

Unable to load historical scan data