Security Scan Report: elster-de-eportal.firebaseapp.com

Site favicon
Submitted: Oct 26, 2025, 9:36:49 PMCompleted: Oct 26, 2025, 9:37:32 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 1 country across 2 domains to perform 10 HTTP transactions. The main domain is elster-de-eportal.firebaseapp.com.

Submitted URL: https://elster-de-eportal.firebaseapp.com/

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

High‑risk phishing site impersonating ELSTER to harvest credentials.

Risk Factors
Credential harvesting form on a low‑reputation, likely new domain
Brand impersonation of ELSTER on a non‑official domain
Form submits data to an external, unrelated domain
Domain hosted on firebaseapp.com (unusual for official tax services)
Domain lacks reputation and appears newly registered
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇩🇪

German

(50% confidence)

Category

finance banking

(93%)

Domain Information

You're looking at domain 'elster-de-eportal.firebaseapp.com' on the commercial generic top-level domain (.com); it also runs on subdomain 'elster-de-eportal'. Its registrable label 'firebaseapp' stretches across 11 characters containing 5 vowels alongside 6 consonants. Tokenizing the label suggests 3 words: fire, base, app. The median word length lands at four characters. 'fire' most often appears in Danish. Usage also turns up in Norwegian and Chinese (Pinyin) contexts.

Screenshot

Security scan screenshot of https://elster-de-eportal.firebaseapp.com/

Page Load Overview

14.98s
Total Load Time
10
HTTP Requests
2
Domains
422 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:191 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as de

Website Classification

Primary Category

finance banking93% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
93%
government public service
50%
adult content
48%
technology software
39%
download file sharing
34%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5104.16.174.226United States
AS13335CLOUDFLARENET
1199.36.158.100United States
AS54113FASTLY
1104.16.175.226United States
AS13335CLOUDFLARENET
12606:4700::6810:afe2United States
AS13335CLOUDFLARENET
12620:0:890::100United States
AS54113FASTLY
12606:4700::6810:aee2United States
AS13335CLOUDFLARENET
106--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BB02621614F9157A229380E977D6AF0A2FA0D403C81A5684B6FC6BD90FDBD53D8E338D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nBcpVyj9V60aMQdFGH++NiZ5DNYTF/nC9UTso+C5cDIvEtguhv:lQdFy+SvxFQguhv

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8514:g4ACQAAiCASAOGUEEA0xsCOKEo5wgBpxAiLJAAXHBAKAOYzoDQQIDAE7qTACEYSMWEoqsACBoAaBNYBQRACAAVJCiCCSQyhD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181c18180000
Perceptual Hash:cdd926729c98c963
Difference Hash:9f6032b2b2b27064
Wavelet Hash:c7a03cbe3c3c383c
Color Hash:#6ce096

Scan History

Scan history not available

Unable to load historical scan data