Security Scan Report: doc-ythvvbc.vercel.app

Submitted: Sep 27, 2026, 5:50:27 PMCompleted: Sep 27, 2026, 5:51:05 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 82%

9
Risk Score

Credential phishing page on a free vercel.app subdomain: a password-capturing 'Email/Password' login with an inert javascript:void(0) form action and phishing-kit hidden fields, plus a threat-intel phishing report on the primary domain.

Risk Factors (5)
Credential-collecting login form (email + password) on a hosting-platform subdomain
Primary domain reported as phishing by threat intelligence
Disguised/inert form action (javascript:void(0)) — no legitimate submission endpoint
Orphan hidden fields (pdf1, address, email, type) consistent with a phishing kit
Unranked domain with no verifiable reputation; creator age of the subdomain is unknown
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'doc-ythvvbc.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'doc-ythvvbc'. The registrable portion 'vercel' spans 6 characters with 2 vowels and four consonants. Segmentation suggests two words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://doc-ythvvbc.vercel.app/

Page Load Overview

0.62s
Total Load Time
371 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:已下架
Text Length:219 chars
Detector Agreement:100%
Language mismatch: Declared as 已下架 but detected as en

Website Classification

Primary Category

adult content29% confidence
Type: webapp
Method: ml+structural

All Detected Categories

adult content
29%
news media journalism
29%
finance banking
28%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1564.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0192.178.183.95Google · CDNUnited States
AS15169Google LLC
0151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0142.251.14.95Google · CDNUnited States
AS15169Google LLC
0104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.150.119Google · CDNUnited States
AS15169Google LLC
054.211.176.164Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
0104.21.26.223Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1516--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BD4484B0E20C20DA7336C44FBF81B6A962B5F369D5514DA6F21F2C5C4EC268611E2F39

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:LIlMIpu80PxXE4YXJgndFTfy9lQOw/71gIuiHlqqm68lDbNBmbfNyHT2Ic7c1+Y0:Ji8Px04YXGdFTyHQ/Z6woHzt09Kk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:260810:ExSy4sDIWcgNCCICBYUGRIlGgIRDGKAFgCFCEJFgA3JFGADwIUKRv6AB4BJANuAdGVTekIQSAkYoJtUBAaoUCzDEBA4gDYob

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:88cc3333337733cc
Difference Hash:4db3b3b3b34d3101
Wavelet Hash:2f1b1b1b1b070f0f
Color Hash:#bfd279

Scan History

Scan history not available

Unable to load historical scan data