Security Scan Report: auth-device-online.firebaseapp.com

Redirected to:
https://www.lloydsbank.com/
Site favicon
Submitted: Oct 8, 2026, 5:55:08 AMCompleted: Oct 8, 2026, 5:56:20 AMpubliccompleted

This website contacted 80 IPs in 3 countries across 55 domains to perform 296 HTTP transactions. The main domain is lloydsbank.com and was registered 21 years ago.

Submitted URL: https://auth-device-online.firebaseapp.com/

Effective URL:

https://www.lloydsbank.com/
Redirected

AI Security Verdict

High Risk

Confidence: 65%

7
Risk Score

This page runs a device-code sign-in lure used to take over accounts — rated high risk on that basis.

Risk Factors (2)
Entry host auth-device-online.firebaseapp.com is a free/instant hosting subdomain of unknown creation date used purely as a redirector
Multi-hop redirect (3 hops) crossing from an unrelated hostname to a bank domain
Domain age information unavailable

Details

Page Title

Online

Scan Type

public

Domain Name Analysis

You're looking at domain 'auth-device-online.firebaseapp.com' on the commercial generic top-level domain (.com); it also runs on subdomain 'auth-device-online'. The second-level label 'firebaseapp' is 11 characters long split between five vowels and 6 consonants. Breaking it apart gives 3 words: fire, base, app. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://auth-device-online.firebaseapp.com/

Page Load Overview

2.02s
Total Load Time
5.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:15,558 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking83% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
83%
adult content
62%
government public service
40%
corporate
35%
healthcare medical
35%

Detected Features

Search
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
59199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
323.67.133.122Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
3143.204.181.43Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
352.222.236.7Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
354.195.115.155Aws · CLOUDDublin, Leinster, Ireland
AS16509Amazon.com, Inc.
3143.204.181.125Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
323.197.134.183Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
323.52.180.163Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
29680--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12D5186DE6C84D018DC362F1A61D4F804478AFE2B5838CCDE63A75194C342FA56B5A81F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:b1oPcoZGdoxoLoUoGp6fl3MAV3pS2DGffF/JCGlj:Bo7+p6fl3MA3pS2D0/JCkj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2783:AAQiQAIAA6IQJQAAQABghUAAQAAIhCAAOQMAAAgBACEIIAogAAAABAAAAAARAAKAAAUAIKAEQAQIBAAEABAAYQoAAIBAQBoB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:04060000003fffff
Perceptual Hash:9034ff4a4aea4d65
Difference Hash:995c96d5d5fd0c1b
Wavelet Hash:04070201457fffff
Color Hash:#6a2d86

Scan History

Scan history not available

Unable to load historical scan data