Security Scan Report: tricodingrind.firebaseapp.com

Redirected to:
https://toumesefofor-shagun-bresse.eu/programme/?pwd=biongtdf
Submitted: Sep 12, 2026, 6:13:48 PMCompleted: Sep 12, 2026, 6:14:28 PMpubliccompleted

Summary

This website contacted 1 IP in 1 country across 2 domains to perform 3 HTTP transactions. The main domain is toumesefofor-shagun-bresse.eu and was registered 13 years ago.

Submitted URL: https://tricodingrind.firebaseapp.com

Effective URL: https://toumesefofor-shagun-bresse.eu/programme/?pwd=biongtdfRedirected

AI Security Verdict

Moderate Risk

Confidence: 78%

5
Risk Score

Firebase-hosted subdomain flagged for clickfix/etherhiding/smartloader malware and redirecting to an unrelated .eu domain with an obfuscated path. Treat as malicious.

Risk Factors
Content-malware threat-intelligence match on the primary domain (clickfix/etherhiding/smartloader)
Cross-domain redirect from firebaseapp.com to a suspicious, unrelated .eu domain
Obfuscated query parameter (?pwd=) in the destination URL
Safety Factors
No credential, password or payment forms detected on the captured page
No JavaScript malware (YARA) patterns or cross-origin credential exfiltration detected
No network IDS alerts observed
No concrete malicious signal (no IoC / YARA / Safe-Browsing / IDS / credential form / brand impersonation) — elevated risk rested on domain age or reputation alone; clamped from 8 to 5
Domain age information unavailable

Details

Page Title

502 Bad Gateway

Scan Type

public

Language

🇧🇩

BN

(50% confidence)

Category

healthcare medical

(78%)

Domain Information

The domain name 'tricodingrind.firebaseapp.com' uses the commercial generic top-level domain (.com) with subdomain 'tricodingrind'. The second-level label 'firebaseapp' is 11 characters long containing 5 vowels alongside six consonants. Breaking it apart gives three words: fire, base, app. Average segment length settles at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tricodingrind.firebaseapp.com

Page Load Overview

2.97s
Total Load Time
3
HTTP Requests
2
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇧🇩Bengali
Code: bn
Confidence:50%
Script:Unknown
Direction:ltr

Detection Details

Language Code:bn
Detection Confidence:50%
Script Type:Unknown
Text Length:249 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical78% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
78%
documentation technical
65%
news media journalism
62%
finance banking
61%
adult content
52%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3199.36.158.100United States
AS54113Fastly, Inc.
31--

Page Statistics

3
Requests
2
Unique Domains
1.0 KB
Total Size

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B2F0267BCDA0248C646456CB4B9CBE6B6A89F069C437081B49287463CB0934C42E7498

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:ECDC/TBLKkq5YgUOUXrN/6oFmK6KSJuITcgbXUCUarSTbGnZiIm+dUn:ECDAdC+OEpFmK6Km53ECUaGeZdU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:7546d31dc350da2681968b11ed013488

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#c387c5

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data