Security Scan Report: invoice.event-refund.com

Redirected to: https://invoice-request-refund-meta-ads.surge.sh/invoice

Submitted: Nov 13, 2025, 5:51:27 AMCompleted: Nov 13, 2025, 5:52:28 AMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 0 countries across 4 domains to perform 7 HTTP transactions. The main domain is invoice-request-refund-meta-ads.surge.sh and was registered NaN years ago.

Submitted URL: http://invoice.event-refund.com/

Effective URL: https://invoice-request-refund-meta-ads.surge.sh/invoiceRedirected

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

Likely phishing site impersonating Meta support; do not provide any information.

Risk Factors
Brand impersonation on a non‑official, unranked domain
Multiple redirects that obscure the final destination
Use of a Surge.sh subdomain with brand‑related keywords (meta‑ads)
Page title mimics official support page without legitimate backing
Domain age information unavailable

Details

Page Title

Meta Business Support

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

social media network

(72%)

Domain Information

The domain name 'invoice.event-refund.com' uses the commercial generic top-level domain (.com), featuring subdomain 'invoice'. Count 12 characters in 'event-refund' holding 4 vowels versus seven consonants, plus one hyphen. Word splitting yields two words: event, refund. Average segment length settles at 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://invoice.event-refund.com/

Page Load Overview

16.81s
Total Load Time
7
HTTP Requests
4
Domains
49 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:705 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network72% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
72%
corporate business
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
0199.60.103.177UnknownUnknown
0188.166.132.94UnknownUnknown
045.55.72.95UnknownUnknown
0172.67.68.225UnknownUnknown
0199.60.103.77UnknownUnknown
02606:4700:20::ac43:44e1UnknownUnknown
02606:4700:20::681a:305UnknownUnknown
02606:4700:20::681a:205UnknownUnknown
0104.26.2.5UnknownUnknown
0104.26.3.5UnknownUnknown
710--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1979131DBD8931106B95341B42FE3AB5627A4D007D58EC8A43EDD929CCF81ED2CA9338D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nqUYDE+YOYLY2Y5Trwc1WlOw3w8hui4mwExAot4r4t8+MhFM3VFKJ:qUYY+YOYLY2Y5TrwcglOw3w8hui4mLW3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4303:ABAIogAkBEFYQEFFBACoQAAICAZhgAgAA0AAhAgBgAQggxABZgwAAAAAkBwA4BEIBAoBkCQSwAEgAgRBCAkCUICCqggAEAEQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data