Security Scan Report: office365login-1f9d1.firebaseapp.com

Site favicon
Submitted: Sep 27, 2026, 6:55:03 PMCompleted: Sep 27, 2026, 6:55:38 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Deceptive Firebase subdomain styled as an Office 365 login and beaconing to a Telegram bot API — a classic phishing redirect/exfiltration pattern. Do not enter any credentials.

Risk Factors (5)
Deceptive hostname claiming to be an Office 365 login portal on a non-Microsoft domain
Cross-origin POST to api.telegram.org bot endpoint (data exfiltration pattern)
Empty 'Redirecting.....' page with no legitimate content
Hosted on a free, instantly-provisioned Firebase subdomain
Domain not present in Cisco Umbrella top 1M
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'office365login-1f9d1.firebaseapp.com' is registered; it also runs on subdomain 'office365login-1f9d1'. The core label 'firebaseapp' covers 11 characters split between five vowels and 6 consonants. Breaking it apart gives three words: fire, base, app. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://office365login-1f9d1.firebaseapp.com/

Page Load Overview

0.21s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Text Length:16 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
32--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10B119C9BD4E4492747A68CB2142BB3C0CD32CE28544DD66A7DA9E402CD8DB1759C72FD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:k0mW+AdQkQwZpKYdpeGtEh85rE7g7Rv+bC3rvk5B:7mFXabz5Eh85r+oRWeYP

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:934:AAAAAAIAAAgSAAAAAEABAAGAAACIAACAAAAAgEAAAAAAAAAgAAAAAAAAAAAAAAAAgAAAAAgQAAAABAAAQAAQBAAAAACAAAAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:c000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#3a7863

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data