Security Scan Report: refund-advertising-meta.surge.sh

Submitted: Oct 21, 2025, 11:34:53 AMCompleted: Oct 21, 2025, 11:37:48 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 3 domains to perform 4 HTTP transactions. The main domain is refund-advertising-meta.surge.sh and was registered NaN years ago.

Submitted URL: https://refund-advertising-meta.surge.sh/meta

AI Security Verdict

High Risk

Confidence: 80%

7
Risk Score

Site impersonates Meta to lure users with a bogus refund offer – high‑risk phishing.

Risk Factors
Brand impersonation of Meta on an unrelated domain
Unsolicited refund claim targeting Meta advertisers
Potential credential harvesting via the hidden '/confirm.html' link
Domain age information unavailable

Details

Page Title

Meta Business Support

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

social media network

(87%)

Domain Information

The domain name 'refund-advertising-meta.surge.sh' uses the .sh country-code top-level domain and includes subdomain 'refund-advertising-meta'. Count 5 characters in 'surge' containing 2 vowels alongside three consonants. Breaking it apart gives one word: surge. Expect 5 characters per word on average. 'surge' is most common in Portuguese usage. Usage also turns up in Portuguese (Brazil) and English contexts. Overall, 'refund-advertising-meta.surge.sh' reads as Portuguese with single-word simplicity.

Screenshot

Security scan screenshot of https://refund-advertising-meta.surge.sh/meta

Page Load Overview

0.90s
Total Load Time
4
HTTP Requests
3
Domains
49 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:570 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network87% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
87%
corporate business
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2138.68.112.220Frankfurt am Main, Hesse, Germany
AS14061DIGITALOCEAN-ASN
1199.60.103.77United States
AS209242Cloudflare London, LLC
1104.26.3.5United States
AS13335CLOUDFLARENET
0104.26.2.5United States
AS13335CLOUDFLARENET
02606:4700:20::681a:205United States
AS13335CLOUDFLARENET
0199.60.103.177United States
AS209242Cloudflare London, LLC
02606:4700:20::ac43:44e1United States
AS13335CLOUDFLARENET
0172.67.68.225United States
AS13335CLOUDFLARENET
02606:4700:20::681a:305United States
AS13335CLOUDFLARENET
49--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T166811F9BD9A31505B95352B52FE3AB162764D007D58ECCA03EDD928CCF81EC2C99338C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nqUYDE+YOYLY2Y5Trwc1WlOw3w8hui4mwExAot4r4tdAJWXAvrFKJ:qUYY+YOYLY2Y5TrwcglOw3w8hui4mLWw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4172:ADAAIAAkAAEIQEFFBAAgQCAADAJhgAAAA2AAhgAJCABAgRABcAwRAANAMBwAwjEAhAqJFAQCQAFgAAAACAECUoCCqggCAAFA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data