Security Scan Report: customer-iam-297e8.web.app

Site favicon
Submitted: Sep 27, 2026, 1:50:51 AMCompleted: Sep 27, 2026, 1:54:22 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 62%

7
Risk Score

Login page collecting email and password on an anonymous Firebase subdomain while claiming to be the central authentication service of 'NEW Gruppe' — brand claim does not match the hosting domain; do not enter credentials.

Risk Factors (5)
Credential collection form (email + password) on a free/anonymous Firebase Hosting subdomain rather than the brand's own registered domain
Claim of being a corporate central authentication service while the domain does not match the claimed organisation
Unverifiable form action ('javascript:') with client-side-only submission — no legible credential endpoint
Use of the Function() constructor (dynamic code generation), an anti-analysis pattern common in obfuscated login panels
Unranked domain outside the Cisco Umbrella top 1M on a shared-hosting namespace with no attributable creation date
Domain age information unavailable

Details

Page Title

Login NEW

Scan Type

public

Domain Name Analysis

You're looking at domain 'customer-iam-297e8.web.app' on the application-focused generic top-level domain (.app) and includes subdomain 'customer-iam-297e8'. The second-level label 'web' is 3 characters long holding one vowel versus two consonants. Segmentation suggests 1 word: web. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://customer-iam-297e8.web.app/

Page Load Overview

30.90s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:652 chars
Detector Agreement:75%

Website Classification

Primary Category

social media network83% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
83%
technology software
61%
government public service
53%
news media journalism
46%
blog personal website
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
9142.251.14.97Google · CDNUnited States
AS15169Google LLC
935.241.3.184Google · CDNKansas City, Missouri, United States
AS396982Google LLC
9172.217.113.4Google · CDNUnited States
AS15169Google LLC
935.190.14.188Google · CDNKansas City, Missouri, United States
AS396982Google LLC
934.120.28.121Google · CDNKansas City, Missouri, United States
AS396982Google LLC
9172.217.112.4Google · CDNUnited States
AS15169Google LLC
935.201.111.240Google · CDNKansas City, Missouri, United States
AS396982Google LLC
9142.250.154.97Google · CDNUnited States
AS15169Google LLC
9172.217.115.4Google · CDNUnited States
AS15169Google LLC
11412--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C9F21EA2F1E6044F3127082B6C25F3B8773D124C4E41EF74662DBAA913CA7C6DA7B046

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:LfZMekCpBXuOHIgcch3vXiU9Oyw6mhxd28Pwa4gZx3x2cdmIwCEJbfUUdGy+az13:LhsL0dW5OdGzSjMRmzoNJg6u

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:36745:geET0F2syIAIAGYILIg6gTUMxAoACCFyQASQTJoCpDAYAKzAguEhQRE1EemglBCaCMVIMhgAIAJyJeCzSJBhEQDMENwQdAIp

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000183c3c100000
Perceptual Hash:8ab931e4ce9964e6
Difference Hash:b105617961619d61
Wavelet Hash:05013d3d3d3dd101
Color Hash:#ac537e

Scan History

Scan history not available

Unable to load historical scan data