Security Scan Report: axa-cotizador-autos.web.app

Redirected to:
https://axa-cotizador-autos.web.app/inicio
Site favicon
Submitted: Sep 26, 2026, 7:50:46 AMCompleted: Sep 26, 2026, 7:52:29 AMpubliccompleted

This website contacted 32 IPs in 2 countries across 18 domains to perform 60 HTTP transactions. The main domain is axa-cotizador-autos.web.app and was registered 8 years ago.

Submitted URL: https://axa-cotizador-autos.web.app/

Effective URL:

https://axa-cotizador-autos.web.app/inicio
Redirected

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Brand-impersonating insurance page on a free web.app subdomain: hostname claims AXA while the page claims to be HSBC. Primary domain carries a phishing report. Avoid entering personal or financial data.

Risk Factors (4)
Phishing threat-intelligence match on the primary domain (single-source, unverified)
Impersonation of a different entity's brand (HSBC branding on a non-HSBC, non-AXA domain)
Deceptive hostname containing a financial brand while page shows a rival brand
Unknown-age subdomain on a free hosting platform
Domain age information unavailable

Details

Page Title

HSBC

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'axa-cotizador-autos.web.app' is registered; it also runs on subdomain 'axa-cotizador-autos'. The registrable portion 'web' spans 3 characters split between 1 vowel and 2 consonants. Splitting it apart reveals one word: web. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://axa-cotizador-autos.web.app/

Page Load Overview

6.68s
Total Load Time
6.6 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:894 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

finance banking49% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
49%
documentation technical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
29199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1142.251.110.139Google · CDNUnited States
AS15169Google LLC
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1142.251.127.94Google · CDNUnited States
AS15169Google LLC
1104.26.6.111Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.12.191Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.14.97Google · CDNUnited States
AS15169Google LLC
134.144.171.27Google · CDNUnited States
AS396982Google LLC
1142.251.110.113Google · CDNUnited States
AS15169Google LLC
1172.67.72.131Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6032--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16124935044062509AA4388F321DCBB21FADE9271E95551A2F2FC5F6E8EDFC7B03AD724

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:yCbcesojydvBqydIKRMqt7XMj8mhWUdQ0mjcdF6zKJE+xgew8Stu+wweUz7TxeYL:yCbcesojydvBqyd6dQ90YDhSefo2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:218063:AEGlRREiFs0qxnoNUDAoUAFGIkUJwWAAMhCRPiDCB2CHBAZCQgEJpUMACwgBEQGpQXiJDKDnIQCCSYsgQASCDQ30OqQAAKBK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc3c3ffcfc3c7ff
Perceptual Hash:b1cece31c68631ce
Difference Hash:821202321e9e1e26
Wavelet Hash:7ac1c3c3c3c3c3c3
Color Hash:#79d298

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data