Security Scan Report: noventaenergy-ca161.web.app

Submitted: Oct 4, 2026, 1:53:18 AMCompleted: Oct 4, 2026, 1:53:54 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Faux 'Permission Check' page on a free Firebase subdomain embedding a brand-like name, with no reputation and an email-capture form but no password fields. Suspicious, though no credential or payment harvesting was verified.

Risk Factors (5)
Deceptive hostname embedding a brand-like name on an unrelated shared hosting namespace
Auto-generated-looking subdomain suffix (ca161) consistent with disposable phishing infrastructure
Vague security-themed 'Permission Check / Authenticate' interstitial with no identified owner
Hidden 'fingerprint' field used for visitor tracking/fingerprinting rather than stated purpose
Unranked domain collecting email address with a boilerplate security-assurance message
Safety Factors (6)
No threat-intelligence matches against the page or its resources
No JavaScript malware (YARA) patterns detected
No network IDS alerts
No cross-origin credential submission or credential exfiltration detected
No password or payment fields present in the captured DOM
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 5
Domain age information unavailable

Details

Page Title

Authentication

Scan Type

public

Domain Name Analysis

You're looking at domain 'noventaenergy-ca161.web.app' on the application-focused generic top-level domain (.app) and includes subdomain 'noventaenergy-ca161'. The second-level label 'web' is 3 characters long containing 1 vowel alongside two consonants. It segments into 1 word: web. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://noventaenergy-ca161.web.app/

Page Load Overview

0.44s
Total Load Time
3 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:85 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service45% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
45%
documentation technical
44%
healthcare medical
36%
news media journalism
30%
technology software
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1172.67.74.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.10.233Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
33--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14E61C8CBF5F30852B917666867A353043778C0075A88CD593E9CB7A88F8465585FB7CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TBRuqnsUnrFSRTGY/7zQCu/Lk6klAHpje:VRuqnsUrFWGY/wBlBe

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3215:EAAEkQAAhACBgJgAAcQIAAREEADCMUAAGAGgBABAAAkDABAAUQAAQIAoAEICAAjEAxAJAgAWAyAAGiIBAAgAMgARBQIIAQAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6cc993366cc9c32
Difference Hash:0008000c4d000800
Wavelet Hash:3c3c3c2407073f3f
Color Hash:#71bf40

Other Hashes

Crop Resistant:0008000c4d000800

Scan History

Scan history not available

Unable to load historical scan data