Security Scan Report: invoice-29002.fwh.is

Redirected to: https://invoice-29002.fwh.is/index.php?i=1

Submitted: Feb 3, 2026, 1:42:39 AMCompleted: Feb 3, 2026, 1:44:14 AMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 2 countries across 2 domains to perform 28 HTTP transactions. The main domain is invoice-29002.fwh.is and was registered NaN years ago.

Submitted URL: https://invoice-29002.fwh.is/[email protected]

Effective URL: https://invoice-29002.fwh.is/index.php?i=1Redirected

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Phishing login page collecting credentials; do not enter any information.

Risk Factors
Credential harvesting form (email + password) on non‑official domain
Unranked domain with suspicious login page
Domain age 458 days (newer than typical established services)
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Language

🇪🇸

Spanish

(29% confidence)

Category

social_media

(50%)

Domain Information

The domain 'invoice-29002.fwh.is' uses the Icelandic country-code top-level domain (.is); it also runs on subdomain 'invoice-29002'. Its registrable label 'fwh' stretches across 3 characters split between zero vowels and three consonants. Tokenizing the label suggests two words: f, wh. Expect 1.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://invoice-29002.fwh.is/index.php?email=eriq@sekure.net

Page Load Overview

19.31s
Total Load Time
28
HTTP Requests
2
Domains
199 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:29%
Script:Latin
Direction:ltr

Detection Details

Language Code:es
Detection Confidence:29%
Script Type:Latin
HTML Lang Attribute:en
Text Length:1,288 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

social_media50% confidence
Type: webapp
Method: structural

All Detected Categories

social_media
50%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.26.8.174United States
AS13335Cloudflare, Inc.
7185.27.134.252United Kingdom
AS34119Wildcard UK Limited
7104.26.9.174United States
AS13335Cloudflare, Inc.
7172.67.71.120United States
AS13335Cloudflare, Inc.
284--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18B031A2620B900B3069644D93C7F631939B6E323590F8D48B47D8B949FA2FCFEDA3559

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:X+TZmXg85NEvW8Xn5qoofJ7kkIrTr5e6pr:uTZmXZ5NEvzqRkkIrTr5e6pr

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:39765:AIIijopHPQJhikcDEhCIEoqAuFjOw3qwhQAIAAC0JioIQGBFRgMjBWAGVjEhdViZQARSxGlIXgAERQwVhzIEyhVDZiQAEC0U

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7c3e7ffff
Perceptual Hash:b33398cc6cb29999
Difference Hash:0c0c0c0c16080000
Wavelet Hash:f8e0e4e4c0e4f0f0
Color Hash:#d279b6

Other Hashes

Crop Resistant:0c0c0c0c16080000

Scan History

Scan history not available

Unable to load historical scan data