Security Scan Report: waitingpackageco.web.app

Submitted: Oct 3, 2026, 11:53:06 AMCompleted: Oct 3, 2026, 11:53:42 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Bare 'confirm you are human' gate with a broken reCAPTCHA on a free .web.app subdomain, and the primary domain carries a single-source phishing report. No forms detected, but the pattern fits a phishing landing shell — treat as high risk.

Risk Factors (4)
Single-source phishing Indicator of Compromise naming the primary domain of this page
Minimal 'human verification' interstitial with a non-functional CAPTCHA and no legitimate site content — typical of a phishing/redirect gate
Free instant-publish subdomain on a shared hosting platform with no attributable creation date
Unranked domain with no reputation footprint
Domain age information unavailable

Details

Page Title

Verification

Scan Type

public

Domain Name Analysis

The domain 'waitingpackageco.web.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'waitingpackageco'. Its registrable label 'web' stretches across 3 characters with one vowel and two consonants. Segmentation suggests one word: web. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://waitingpackageco.web.app/

Page Load Overview

1.73s
Total Load Time
805 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:76 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical57% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
57%
news media journalism
41%
government public service
40%
adult content
27%
finance banking
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
1142.251.152.119Google · CDNUnited States
AS15169Google LLC
1142.251.127.94Google · CDNUnited States
AS15169Google LLC
1142.251.154.119Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
95--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B051B6B7259414255D1383B294F1B6C97422C60BF9C0E2E1BCE86AB8BFC5DB3C887569

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TXJ+CKzrlfr9m7QpZcqgjKX8C7BmYYdshOjrxm3OZaNthYy11rZjnOzV:TkpzrprwQLwf4OfaNtOynlOp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3115:JAhAoAAAIAQMCABAAAAACAAAgABAACQQA5oEwAAAAEAABQCAFCECAIAgEBgQFIABABAAyIUAEggAgEAhAEAIABCAoAACgAAB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:080c180000000000
Perceptual Hash:999933666ccccccc
Difference Hash:105a320000000000
Wavelet Hash:d8c8d8c0f0f0f0f0
Color Hash:#c58799

Other Hashes

Crop Resistant:105a320000000000

Scan History

Scan history not available

Unable to load historical scan data