Security Scan Report: refusion-annonce-meta.surge.sh

Submitted: Oct 17, 2025, 11:00:22 AMCompleted: Oct 17, 2025, 11:03:06 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 3 domains to perform 4 HTTP transactions. The main domain is refusion-annonce-meta.surge.sh.

Submitted URL: https://refusion-annonce-meta.surge.sh/account

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing site impersonating Meta, likely used to harvest credentials or payments.

Risk Factors
Brand impersonation on an unusual, unranked domain
New/unknown domain age with no reputation
Social engineering claim of a refund to lure users
Use of a generic hosting subdomain (surge.sh) to host the page
Domain age information unavailable

Details

Page Title

Meta Business Support

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

unknown

(0%)

Domain Information

The domain name 'refusion-annonce-meta.surge.sh' uses the .sh country-code top-level domain; it also runs on subdomain 'refusion-annonce-meta'. Count 5 characters in 'surge' holding 2 vowels versus three consonants. Word splitting yields 1 word: surge. 'surge' most strongly signals Portuguese. You will also see it in Portuguese (Brazil) and English contexts. Taken together, it feels Portuguese with single-word simplicity.

Screenshot

Security scan screenshot of https://refusion-annonce-meta.surge.sh/account

Page Load Overview

5.48s
Total Load Time
4
HTTP Requests
3
Domains
49 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:570 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2138.68.112.220Frankfurt am Main, Hesse, Germany
AS14061DIGITALOCEAN-ASN
1104.26.3.5United States
AS13335CLOUDFLARENET
1199.60.103.177United States
AS209242Cloudflare London, LLC
0104.26.2.5United States
AS13335CLOUDFLARENET
02606:4700:20::ac43:44e1United States
AS13335CLOUDFLARENET
02606:4700:20::681a:205United States
AS13335CLOUDFLARENET
02606:4700:20::681a:305United States
AS13335CLOUDFLARENET
0172.67.68.225United States
AS13335CLOUDFLARENET
0199.60.103.77United States
AS209242Cloudflare London, LLC
49--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T152811F9BD9A31505B95352B52FE3AB162764D007D58ECCA03EDD928CCF81EC2C99338C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nqUYDE+YOYLY2Y5Trwc1WlOw3w8hui4mwExAot4r4td3JWXAvrFKJ:qUYY+YOYLY2Y5TrwcglOw3w8hui4mLWB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4172:ADAAIAAkAAEIQEFFBAAgQCAADAJhgAAAA2AAhgABCABAgRABcAwRAANAMBwAwjEAhAqJFAQCQAFgAAAACAECUoCCqggCAAHA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data