Security Scan Report: att-rehome.firebaseapp.com

Redirected to:
https://att-rehome.firebaseapp.com/login
Site favicon
Submitted: Sep 23, 2026, 12:45:16 AMCompleted: Sep 23, 2026, 12:46:57 AMpubliccompleted

This website contacted 5 IPs in 1 country across 5 domains to perform 12 HTTP transactions. The main domain is att-rehome.firebaseapp.com and was registered 14 years ago.

Submitted URL: https://att-rehome.firebaseapp.com/

Effective URL:

https://att-rehome.firebaseapp.com/login
Redirected

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Login-titled page on a free Firebase subdomain whose 'att-rehome' label mimics a telecom brand, but no credential form, IoC, malware or exfiltration was found. Treat with caution.

Risk Factors
Brand-lookalike subdomain ('att-rehome') on a non-official firebaseapp.com host
Login-themed page on a shared free-hosting namespace with unknown creation date
Safety Factors
No credential or payment fields present in the captured DOM
No Indicators of Compromise or threat-intelligence hits
No JavaScript malware (YARA) or behavioral exfiltration signals
No cross-origin form submissions or credential exfiltration
No network-level IDS alerts
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 4 to 4
Domain age information unavailable

Details

Page Title

Rehome Automation

Scan Type

public

Domain Name Analysis

The domain 'att-rehome.firebaseapp.com' uses the commercial generic top-level domain (.com), featuring subdomain 'att-rehome'. The core label 'firebaseapp' covers 11 characters containing five vowels alongside 6 consonants. Breaking it apart gives three words: fire, base, app. Average segment length settles at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://att-rehome.firebaseapp.com/

Page Load Overview

4.29s
Total Load Time
465 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:37 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as it

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
2172.217.118.4Google · CDNUnited States
AS15169Google LLC
2172.217.114.4Google · CDNUnited States
AS15169Google LLC
2142.251.110.97Google · CDNUnited States
AS15169Google LLC
2216.239.34.36Google · CDNUnited States
AS15169Google LLC
125--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T199A18664E422B1F9269BCDAF7895FC4B4B81C801CC1C4D58B8C32368B4CCA4796E3BC8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:NZVPp7YUtUVWLZy8Nd+ZGAdKvINbDkenFwieM6Surf3Fyj:NZtp7wWty8Nd+ZGAdKUsVieM6Zf3Fyj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4958:AAMIDAAkCcACAAIAKSGMEAojJIIAEkCgQgKRKEMUAHggTAADAAIPALAEAESAFwCgYCBhgSABQAAHEBiACAIQRQAAgFJCEGEE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7c3c7e7ff
Perceptual Hash:f3cdcc3332cd02cc
Difference Hash:800c004c4c4c0c00
Wavelet Hash:00fef6c2c2c2c2fe
Color Hash:#2d866d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data