Security Scan Report: o2-billing-recovery.web.app

Site favicon
Submitted: Sep 29, 2026, 2:54:45 AMCompleted: Sep 29, 2026, 2:55:23 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 60%

6
Risk Score

Deceptive 'o2-billing-recovery' hostname on a free Firebase subdomain suggests O2 brand impersonation, but the page is broken/empty with no forms, no malware and no threat-intel hits. Suspicious but unconfirmed.

Risk Factors (3)
Deceptive hostname implying it belongs to the O2 telecom brand
Free/instant-publish hosting subdomain with unknown creation date (unranked, no Cisco Umbrella reputation)
Empty/broken page whose branding claim cannot be verified as legitimate
Safety Factors (5)
No credential, password, or payment forms found in the captured DOM (0 forms, 0 password fields)
No threat-intelligence Indicators of Compromise matches
No JavaScript malware (YARA) patterns and no native-YARA high-precision hits
No cross-origin credential exfiltration; all scripts served from the site's own domain
Only network IDS alert is informational (external IP lookup to ipapi.co), not a phishing/malware signature
Domain age information unavailable

Details

Page Title

o2

Scan Type

public

Domain Name Analysis

The domain name 'o2-billing-recovery.web.app' uses the application-focused generic top-level domain (.app) with subdomain 'o2-billing-recovery'. The core label 'web' covers 3 characters holding one vowel versus two consonants. It segments into 1 word: web. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://o2-billing-recovery.web.app/

Page Load Overview

1.05s
Total Load Time
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
4104.26.8.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4192.178.183.94Google · CDNUnited States
AS15169Google LLC
4142.251.13.94Google · CDNUnited States
AS15169Google LLC
4142.251.127.94Google · CDNUnited States
AS15169Google LLC
246--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C835CFBBAE476FCABF71140355DE12C30D0EDB03916A22B5B70D94AA590EE746BF940C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:TiOqX+YIU/xZXLby4i6rrx0jk/UFsPHngdbbOqX+YIU/x4jc4i6rrx0jk/UFsPHH:T+OFU/Pvy5EofOFU/Ojc5Eo6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1063733:x4X0YUkgAUI0GMuAAFNAAAGjK0rHOlUVgLwMAWAcJJCMAHx0QLLCQIwAQQCGAwEmA4IShsgJIQ5b6aOSwo2waCiUAQMMgABT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:a2dd887722dd8876
Difference Hash:0000000808000000
Wavelet Hash:0f0f0f0707070f0f
Color Hash:#2d8649

Other Hashes

Crop Resistant:0000000808000000

Scan History

Scan history not available

Unable to load historical scan data