Security Scan Report: thosrhksi-q.firebaseapp.com

Redirected to:
https://mecury.shop/ROK
Submitted: Sep 29, 2026, 1:52:37 PMCompleted: Sep 29, 2026, 1:53:29 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Anonymous Firebase subdomain redirects to unranked mecury.shop, which serves only a 502 error stub; no forms or Indicators of Compromise, but the classifier flags phishing. Suspicious with weak concrete evidence.

Risk Factors (3)
Cross-domain redirect from an anonymous, randomly named Firebase hosting subdomain to an unrelated low-reputation domain (mecury.shop)
ML content classifier returns 'phishing scam' with 67% confidence
Destination host serves only an error/redirect stub with no visible legitimate purpose
Safety Factors (4)
No credential, password, or payment fields present (forms = 0)
No Indicators of Compromise matched against the page or its resources
No YARA JavaScript malware patterns and no obfuscated script with a network sink
No network-level IDS alerts and no known malicious kit signatures
Domain age information unavailable

Details

Page Title

502 Bad Gateway

Scan Type

public

Domain Name Analysis

You're looking at domain 'thosrhksi-q.firebaseapp.com' on the commercial generic top-level domain (.com), featuring subdomain 'thosrhksi-q'. The registrable portion 'firebaseapp' spans 11 characters containing 5 vowels alongside 6 consonants. Splitting it apart reveals three words: fire, base, app. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://thosrhksi-q.firebaseapp.com/

Page Load Overview

0.27s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:64%
Script:Latin
Direction:ltr

Detection Details

Text Length:84 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam67% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

phishing scam
67%
news media journalism
38%
adult content
37%
real estate property
30%
government public service
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
31--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13AE0ABCF2A0030A201815109E556F42CED97CCE8A4998574C8D256450A15225B466BA2

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:A0gYs0kMRJlKIOxSslJmmHK3baMXeKP1qbKZgIhSAhuPoljQ6s1foAljo8n:AAkM80sHxHsbaMXz7XxhuPqWFoAho8n

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:a9225c7982e19a8a02875644ef522220

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#2d8649

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data