Security Scan Report: invoice-request-refund-meta-ads.surge.sh

Submitted: Nov 13, 2025, 6:22:00 AMCompleted: Nov 13, 2025, 6:22:42 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 3 domains to perform 4 HTTP transactions. The main domain is invoice-request-refund-meta-ads.surge.sh.

Submitted URL: https://invoice-request-refund-meta-ads.surge.sh/invoice

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

High‑risk phishing site impersonating Meta; likely a scam.

Risk Factors
Brand impersonation on an unranked, newly created domain
Domain likely less than 90 days old mimicking a well‑known brand
Suspicious subdomain and path suggesting fraudulent invoice/refund request
Domain age information unavailable

Details

Page Title

Meta Business Support

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

social media network

(72%)

Domain Information

The domain 'invoice-request-refund-meta-ads.surge.sh' uses the .sh country-code top-level domain; it also runs on subdomain 'invoice-request-refund-meta-ads'. The second-level label 'surge' is 5 characters long holding two vowels versus 3 consonants. Splitting it apart reveals one word: surge. Average segment length settles at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://invoice-request-refund-meta-ads.surge.sh/invoice

Page Load Overview

2.48s
Total Load Time
4
HTTP Requests
3
Domains
49 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:705 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network72% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
72%
corporate business
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.67.68.225United States
AS13335CLOUDFLARENET
0199.60.103.177United States
AS209242Cloudflare London, LLC
0188.166.132.94Amsterdam, North Holland, Netherlands
AS14061DIGITALOCEAN-ASN
0104.26.2.5United States
AS13335CLOUDFLARENET
0199.60.103.77United States
AS209242Cloudflare London, LLC
0104.26.3.5United States
AS13335CLOUDFLARENET
02606:4700:20::ac43:44e1United States
AS13335CLOUDFLARENET
02606:4700:20::681a:305United States
AS13335CLOUDFLARENET
02606:4700:20::681a:205United States
AS13335CLOUDFLARENET
49--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1979131DBD8931106B95341B42FE3AB5627A4D007D58EC8A43EDD929CCF81ED2CA9338D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nqUYDE+YOYLY2Y5Trwc1WlOw3w8hui4mwExAot4r4t8+MhFM3VFKJ:qUYY+YOYLY2Y5TrwcglOw3w8hui4mLW3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4303:ABAIogAkBEFYQEFFBACoQAAICAZhgAgAA0AAhAgBgAQggxABZgwAAAAAkBwA4BEIBAoBkCQSwAEgAgRBCAkCUICCqggAEAEQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data