Security Scan Report: sportsbg-f9609.firebaseapp.com

Submitted: Oct 4, 2026, 1:53:41 AMCompleted: Oct 4, 2026, 1:54:15 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Sparse Firebase-hosted 'Permission Check' page asking only for an email (no password or payment fields), with no owner identified. No scanner hit, no impersonation and no exfiltration, but the unknown-age, unranked gate is not trustworthy enough to enter data blindly.

Risk Factors (3)
Unidentified authentication/email-collection gate on a free hosting platform subdomain with no disclosed owner or purpose
Effectively unknown-age, unranked shared-hosting tenant (Firebase) — reputation and platform age are not attributable to this page
Reassurance text ('secure and encrypted') paired with a request for the user's email, typical of low-transparency access gates
Safety Factors (4)
No password, disguised-password or payment fields present — no credential or payment harvesting
No cross-origin form submission or credential exfiltration detected; all scripts served from the page's own domain
No Indicators of Compromise matches, no JavaScript malware (YARA) patterns, no native-YARA hits, no network IDS alerts
No brand impersonation: the page does not present itself as any other organization
Domain age information unavailable

Details

Page Title

Authentication

Scan Type

public

Domain Name Analysis

You're looking at domain 'sportsbg-f9609.firebaseapp.com' on the commercial generic top-level domain (.com) with subdomain 'sportsbg-f9609'. The registrable portion 'firebaseapp' spans 11 characters containing five vowels alongside six consonants. Splitting it apart reveals 3 words: fire, base, app. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sportsbg-f9609.firebaseapp.com/

Page Load Overview

0.27s
Total Load Time
3 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:85 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service45% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
45%
documentation technical
44%
healthcare medical
36%
news media journalism
30%
technology software
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.26.11.233Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
32--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F061B68BE5A30462BD13526467E353043734C40B5A88CD693E9CB7A8DF8468589FB7CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nBRzqDI99NF12UnrFCRRT61mi1YMYb7/ZJXPpCt0/4zChfk6Bg1VlL8e:nBRuqnsUnrFSRTGY/7zXPpD/Lk6klL8e

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3225:AIAAAMNoBCQAQAAAEgQaAAASICSCgACBBARAAAYAAABoAIAAGAAACgJBAvABQQoAAEEgAABQEAEQQQHG0QgIAIAAACQIICAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e6cc993366cc9c32
Difference Hash:0008000c4d000800
Wavelet Hash:3c3c3c2407073f3f
Color Hash:#44931f

Other Hashes

Crop Resistant:0008000c4d000800

Scan History

Scan history not available

Unable to load historical scan data