Security Scan Report: noventaenergy-ca161.firebaseapp.com

Submitted: Sep 27, 2026, 12:50:34 AMCompleted: Sep 27, 2026, 12:51:52 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 58%

5
Risk Score

Unknown-age Firebase Hosting subdomain with an unexplained 'Permission Check' gate that asks for an email and captures a hidden fingerprint. No malware, IoC, or password/payment form found, so evidence stays circumstantial — do not submit personal data.

Risk Factors (4)
Unknown-age subdomain on a shared free hosting platform (anyone can publish here instantly)
Unranked domain with no established reputation
Email-collection form paired with a hidden device-fingerprint field behind an unexplained access gate
Brand-like company string in the subdomain on a non-official hosting namespace
Safety Factors (6)
No Indicators of Compromise matched against the page or its resources
No JavaScript malware patterns (YARA) detected
No high-precision native-YARA-scanner hits and no known phishing kit in the kit roster
No network IDS (Suricata) alerts
No cross-origin credential submission or credential exfiltration detected
No password, payment, or disguised-password fields in the parsed DOM
Domain age information unavailable

Details

Page Title

Authentication

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'noventaenergy-ca161.firebaseapp.com' is registered; it also runs on subdomain 'noventaenergy-ca161'. Count 11 characters in 'firebaseapp' holding 5 vowels versus six consonants. Tokenizing the label suggests three words: fire, base, app. Average segment length settles at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://noventaenergy-ca161.firebaseapp.com/

Page Load Overview

0.82s
Total Load Time
3 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:85 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical45% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
45%
government public service
44%
healthcare medical
36%
news media journalism
30%
technology software
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1172.67.74.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.11.233Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
33--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13D61C8CBF5F30852B917666867A353043778C0075A88CD593E9CB7A88F8465585BB7CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TBRuqnsUnrFSRTGY/7zQCW/Lk6klAHpje:VRuqnsUrFWGY/wZlBe

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3215:EAAEkQAAhACBgJgAAcQIAAREEADCMUAAGAGABABAAAkDABAAUQAAQIAoBEKCAADEAxAJAgAWAyAAGiIBAAgAMgARBQIIAQAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6cc993366cc9c32
Difference Hash:0008000c4d000800
Wavelet Hash:3c3c3c2407073f3f
Color Hash:#ac5391

Other Hashes

Crop Resistant:0008000c4d000800

Scan History

Scan history not available

Unable to load historical scan data