Security Scan Report: firebox-ssl.com

Site favicon
Submitted: Sep 17, 2026, 5:47:30 AMCompleted: Sep 17, 2026, 5:47:52 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 80%

8
Risk Score

Unofficial domain firebox-ssl.com impersonates WatchGuard and offers a branded Firebox SSL VPN client download while its primary domain is flagged for bumblebee malware — a likely malware-distribution lure. Avoid.

Risk Factors (4)
Content-malware threat-intel match (bumblebee) on the primary domain
Brand impersonation of WatchGuard on the non-official domain firebox-ssl.com
Fake/unofficial software download page for a branded VPN client
Unranked, unestablished domain hosting brand-styled download content
Domain age information unavailable

Details

Page Title

Download Firebox SSL VPN Client | WatchGuard

Scan Type

public

Domain Name Analysis

Domain 'firebox-ssl.com' uses the commercial generic top-level domain (.com) with no subdomain. The registrable portion 'firebox-ssl' spans 11 characters containing three vowels alongside seven consonants, plus 1 hyphen. Breaking it apart gives two words: firebox, ssl. Median word length is 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://firebox-ssl.com

Page Load Overview

1.95s
Total Load Time
103 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:8,347 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software69% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
69%
corporate business
60%
corporate
35%
government public service
28%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
380.249.132.131Netherlands
AS60781LeaseWeb Netherlands B.V.
220.250.198.32Azure · CLOUDZurich, Zurich, Switzerland
AS8075Microsoft Corporation
2150.171.109.104Azure · CLOUDUnited States
AS8075Microsoft Corporation
73--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C1B2B32262F620334AD3D290BA71A35B6B64E907CA17061832FD07AD4FC3DD5C97B5E9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:LwlOFIYdQMx+4HrwbYedMLi5GGOz5MaaEAcy:LwNnkZedci50OkAh

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23656:EgwENMKCIhqyKtaAEx2gmZIYEgsEISkqnMWBIAqGAdEE+IKiyDqwWUhFLIJDC8KC5HRAumJRQBQBCESEB1ElYFCsAaQeYDMA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff01bf3f0f0f0300
Perceptual Hash:aacf70b1d29fc482
Difference Hash:63076b693f1f1fcd
Wavelet Hash:ff813f3f070f0700
Color Hash:#e0e06c

Scan History

Scan history not available

Unable to load historical scan data