Security Scan Report: zany-trouble5d0e254r0r440e45e66d00e0r54.surge.sh

Redirected to: https://rechnungdirekt24.com/

Submitted: Oct 13, 2025, 6:07:34 PMCompleted: Oct 13, 2025, 6:08:16 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 3 countries across 3 domains to perform 5 HTTP transactions. The main domain is rechnungdirekt24.com.

Submitted URL: https://zany-trouble5d0e254r0r440e45e66d00e0r54.surge.sh/

Effective URL: https://rechnungdirekt24.com/Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing site impersonating STRATO; do not provide any data or payments.

Risk Factors
Brand impersonation on a non‑official, newly registered domain
Unranked domain lacking any reputation
Domain age of 0 days (very new)
Urgent payment request without proper payment processing
Domain age information unavailable

Details

Page Title

Ihre Rechnungen - STRATO AG

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

corporate business

(82%)

Domain Information

Within the .sh country-code top-level domain, 'zany-trouble5d0e254r0r440e45e66d00e0r54.surge.sh' is registered, featuring subdomain 'zany-trouble5d0e254r0r440e45e66d00e0r54'. Its registrable label 'surge' stretches across 5 characters containing 2 vowels alongside three consonants. Tokenizing the label suggests one word: surge. Most frequently, 'surge' shows up in Portuguese. You will also see it in Portuguese (Brazil) and English contexts. Overall, 'zany-trouble5d0e254r0r440e45e66d00e0r54.surge.sh' reads as Portuguese with single-word simplicity.

Screenshot

Security scan screenshot of https://zany-trouble5d0e254r0r440e45e66d00e0r54.surge.sh/

Page Load Overview

3.04s
Total Load Time
5
HTTP Requests
3
Domains
17 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:1,127 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business82% confidence
Type: static
Method: ml+structural

All Detected Categories

corporate business
82%
technology software
72%
government public service
69%
cryptocurrency blockchain
68%
finance banking
67%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2138.68.112.220Frankfurt am Main, Hesse, Germany
AS14061DIGITALOCEAN-ASN
1185.15.59.240United States
AS14907WIKIMEDIA
1103.179.189.95Vietnam
AS135905VIETNAM POSTS AND TELECOMMUNICATIONS GROUP
12a02:ec80:300:ed1a::2:bUnited States
AS14907WIKIMEDIA
54--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1534393AAA2F3216A7917A1792BBB57562335C047C50ACC183FCD1344CF867E5AC537AC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:BJwFMpXafA8Qy8FLF72yFdTtW+C/xx+xXPWjSv:7wCFafALy8ZJ2yrgX+1P7v

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:55884:gQhwCsIgggoAPZCYgwYQHHEACEFADiICA0jMmQEMIgBYAEBTBwiBE0FxAiaIAKAdw/43gLgzoMoTqBSEUYYVCFIgMA+NADjA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:785c8080ffffffff
Perceptual Hash:dc5cc1c5c47c7c61
Difference Hash:b4b93331ccd4c0c0
Wavelet Hash:701c008094ff7f7f
Color Hash:#c1e06c

Other Hashes

Crop Resistant:b4b93331ccd4c0c0

Scan History

Scan history not available

Unable to load historical scan data