Security Scan Report: customer-iam-test-4a9cc.web.app

Site favicon
Submitted: Sep 27, 2026, 1:50:53 AMCompleted: Sep 27, 2026, 1:54:23 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 65%

7
Risk Score

Firebase-hosted login page collecting email and password while claiming to be the NEW Gruppe central authentication service on a non-NEW, unranked test subdomain. Avoid entering credentials unless the hostname is confirmed as NEW's official identity provider.

Risk Factors (4)
Credential-harvesting login form (email + password) on a shared hosting subdomain
Presents itself as the central authentication service of NEW Gruppe on a domain that does not belong to NEW
Unranked domain with unknown tenant creation date
Development-style hostname (customer-iam-test) for what is presented as a corporate login portal
Domain age information unavailable

Details

Page Title

Login NEW

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'customer-iam-test-4a9cc.web.app' is registered; it also runs on subdomain 'customer-iam-test-4a9cc'. The registrable portion 'web' spans 3 characters containing one vowel alongside two consonants. Splitting it apart reveals 1 word: web. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://customer-iam-test-4a9cc.web.app/

Page Load Overview

27.77s
Total Load Time
1.5 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:607 chars
Detector Agreement:75%

Website Classification

Primary Category

government public service42% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
42%
technology software
38%
adult content
30%
news media journalism
28%
blog personal website
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
11142.251.14.97Google · CDNUnited States
AS15169Google LLC
1135.241.3.184Google · CDNKansas City, Missouri, United States
AS396982Google LLC
11172.217.119.4Google · CDNUnited States
AS15169Google LLC
1135.190.14.188Google · CDNKansas City, Missouri, United States
AS396982Google LLC
11172.217.114.4Google · CDNUnited States
AS15169Google LLC
1134.120.28.121Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1135.201.111.240Google · CDNKansas City, Missouri, United States
AS396982Google LLC
11142.250.154.97Google · CDNUnited States
AS15169Google LLC
11172.217.117.4Google · CDNUnited States
AS15169Google LLC
11210--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T136F2FEA2F1E6044F3127582B6C25F3BC773D125C4E51EF74622DBAA902CA7C6DA7B046

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:W6ZMYkCpBXuOHIgcch3vXiU9Oyw6mhxd28Pwa4gZx3x2cdmIwCEJbfUUdGy+az12:WeSL0dW5OdGzSjMRmzbN1gT7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:36241:A6TCAUJETMMwhKYQKQAIdSSgBERAkCQIcQ1BBBFF0TKLJhGQEmwieQLABeAgkhCKeAVPtkUhhAVIBUeEiJyEpQBIIVIMEMAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000183c3c100000
Perceptual Hash:8ab931e4ce9964e6
Difference Hash:b105617961619d61
Wavelet Hash:0f033f3f3d3d0101
Color Hash:#86442d

Scan History

Scan history not available

Unable to load historical scan data