Security Scan Report: axa-cotizador-autos.web.app

Redirected to:
https://axa-cotizador-autos.web.app/inicio
Site favicon
Submitted: Jul 18, 2026, 11:51:56 PMCompleted: Jul 18, 2026, 11:53:39 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 1 country across 3 domains to perform 2 HTTP transactions. The main domain is axa-cotizador-autos.web.app and was registered NaN years ago.

Submitted URL: https://axa-cotizador-autos.web.app/

Effective URL: https://axa-cotizador-autos.web.app/inicioRedirected

AI Security Verdict

Moderate Risk

Confidence: 82%

5
Risk Score

The site impersonates HSBC on an unranked web.app subdomain with unknown age, posing a high risk of phishing.

Risk Factors
Brand impersonation of a major financial institution
Unranked subdomain on a generic hosting platform
Unknown subdomain age
Safety Factors
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 7 to 3
Domain age information unavailable

Details

Page Title

HSBC

Scan Type

public

Language

🇪🇸

Spanish

(50% confidence)

Category

finance banking

(66%)

Domain Information

Within the application-focused generic top-level domain (.app), 'axa-cotizador-autos.web.app' is registered, featuring subdomain 'axa-cotizador-autos'. The second-level label 'web' is 3 characters long with 1 vowel and two consonants. Breaking it apart gives one word: web. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://axa-cotizador-autos.web.app/

Page Load Overview

2.85s
Total Load Time
58
HTTP Requests
18
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:894 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

finance banking66% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
66%
documentation technical
30%
adult content
27%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
20192.178.183.95Google · CDNUnited States
AS15169Google LLC
19199.36.158.100United States
AS54113Fastly, Inc.
19142.251.20.101Google · CDNUnited States
AS15169Google LLC
583--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13924B45044062509AA4388F321DCBB21F9CE9271E95691A2F6FC5F6E8FDFC7B026D724

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:+CbcesojydvBnydIKPXPt7XMj8mhWUdQ0mjcdF6zKTma+qgu38Gt++vweUz24xu7:+CbcesojydvBnydcdQ7HEq5lq6sB/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:224691:YR+IVJmEaAE8AIxAAQ2w1AMEmwBGAGEwVCiFIRJPAjUQUKYMYD75OXCCJIRWMALCArCxGBUsCMIukKUmAPkqeQBNggYSaIsF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffc381c3ffc7efff
Perceptual Hash:b93c8693c66731c6
Difference Hash:921f1b2b189e1e26
Wavelet Hash:c3818181cfc3c7df
Color Hash:#2d6fd2

Scan History

Scan history not available

Unable to load historical scan data