Security Scan Report: crmoutlec.firebaseapp.com

Redirected to:
https://croumnuel.top/?pwd=cm
Submitted: Sep 29, 2026, 5:54:58 PMCompleted: Sep 29, 2026, 5:55:47 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Free Firebase subdomain redirecting to an unranked .top host with a '?pwd=' parameter and a phishing ML label; destination served only a 502 error. Suspicious infrastructure, but no credential form or malware was actually delivered.

Risk Factors (4)
Cross-domain redirect from a free hosting platform subdomain to an unrelated, unranked .top domain
'?pwd=' parameter in the final URL suggests credential-oriented redirect infrastructure
Machine-learning content classifier flags phishing scam (67%)
Destination domain has no reputation and no known age
Safety Factors (6)
No credential, password or payment forms were parsed from the captured DOM (0 forms, 0 password fields, 0 payment fields)
No YARA/JavaScript malware patterns, no inline network/crypto APIs
No threat-intelligence Indicator of Compromise matches and no network IDS alerts
No third-party scripts or cross-origin credential exfiltration
Only content served was a '502 Bad Gateway / Name or service not known' error page
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 5 to 5
Domain age information unavailable

Details

Page Title

502 Bad Gateway

Scan Type

public

Domain Name Analysis

Domain 'crmoutlec.firebaseapp.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'crmoutlec'. The registrable portion 'firebaseapp' spans 11 characters holding five vowels versus 6 consonants. It segments into 3 words: fire, base, app. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://crmoutlec.firebaseapp.com/

Page Load Overview

0.33s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:87 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam67% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

phishing scam
67%
news media journalism
38%
adult content
37%
documentation technical
30%
real estate property
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3199.36.158.100Fastly · CDNUnited States
AS54113Fastly, Inc.
31--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T122F00ECE2EE030D200528008F8E2F516EC4794EF5548C468F9CCAA486F08B06A8E7BB1

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:/wMxCWkqJmr2xHJT9jX3EdZPXxhuN4WLAho8TmoQb:/wMxCWrlRjkXXvtWEhK

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:568:CAACEBAAAAAAAAAAAAAAAEAAAAAAAAACAAAAAACAAAgAAAAAABICAIAAAAAAAAAAAAAQAAAAAAAABCAAAAAAAAAAAAAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:870707070f0f1f3f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#2dc5d2

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data