Security Scan Report: sessionid089-dhlgateway.firebaseapp.com

Submitted: Sep 27, 2026, 11:53:19 PMCompleted: Sep 27, 2026, 11:54:10 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 60%

5
Risk Score

Impersonates DHL shipping on free Firebase subdomain with unknown age, but no credential forms; threat intel on is.gd is generic abuse reputation only.

Risk Factors (4)
Impersonates DHL shipping brand on a non-DHL domain
Hosted on free Firebase hosting platform; subdomain creation date unknown
Unranked in Cisco Umbrella top 1M
Loads URL shortener is.gd, which has a generic abuse-reputation threat-intel match
Safety Factors (4)
No forms, password fields, payment fields, or credential exfiltration detected
No JavaScript YARA malware patterns detected
No known malicious kits identified
hCaptcha is used, a legitimate anti-bot service
Domain age information unavailable

Details

Page Title

Track Your Shipment

Scan Type

public

Domain Name Analysis

You're looking at domain 'sessionid089-dhlgateway.firebaseapp.com' on the commercial generic top-level domain (.com) with subdomain 'sessionid089-dhlgateway'. The core label 'firebaseapp' covers 11 characters with five vowels and 6 consonants. Word splitting yields three words: fire, base, app. Median word length is 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sessionid089-dhlgateway.firebaseapp.com/

Page Load Overview

0.43s
Total Load Time
949 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:19 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.19.230.21Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.12.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.83.132Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.19.229.21Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
97--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D3C1C6F816321D186CBAB686E46C77CDC2325E07FE81346874ED521033CEDEA419FA66

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nBRYPGRZJ40aTvj6VvBBdevksLmC2ZRENUAkLBINHIjkAQrsavksLmC2ZRENUAkh:PooZ2BjgvBBhU2ZRENUAkLBINfwU2ZRN

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6047:hDAAhCgETAiBICBBIRHRBEICQlAEEBRBEKEoIjMADIUNggAIGSLAmABYBCMQoEwKEGCOCBgIAChBgAhRCIFSgEEBmsIj4AGN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7ffffffffffffff
Perceptual Hash:e666666666666626
Difference Hash:0c00000000000000
Wavelet Hash:e7ffffff00000000
Color Hash:#583a78

Other Hashes

Crop Resistant:0c00000000000000

Scan History

Scan history not available

Unable to load historical scan data