Security Scan Report: zimupdate-portal.vercel.app

Submitted: Sep 27, 2026, 10:50:17 AMCompleted: Sep 27, 2026, 10:51:25 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Fake Zimbra webmail login on a vercel.app subdomain that harvests email and password via a cross-origin form to submit-form.com. Brand impersonation plus credential exfiltration — do not enter credentials.

Risk Factors (5)
Credential (email + password) form submits to external domain submit-form.com, not to the page's own origin
Impersonation of Zimbra/Synacor webmail login on an unrelated vercel.app subdomain
Suricata HIGH IDS alert for form exfiltration to submit-form.com
Single-source phishing threat-intel report on the primary domain
No reputation (unranked in Cisco Umbrella), no legitimacy indicators, unknown-age shared-hosting subdomain
Domain age information unavailable

Details

Page Title

Zimbra Web Client Sign In

Scan Type

public

Domain Name Analysis

The domain 'zimupdate-portal.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'zimupdate-portal'. The core label 'vercel' covers 6 characters split between two vowels and 4 consonants. Tokenizing the label suggests 2 words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zimupdate-portal.vercel.app/

Page Load Overview

1.47s
Total Load Time
2 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:228 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software57% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
57%
corporate business
51%
government public service
40%
adult content
39%
documentation technical
38%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
264.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
064.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
23--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AE51449695530C10F902B5702FD6CB1235A4C523824ECC793ECDB7ACCF9A9C946A339D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBrlNgOG6P8NFwbAnN5gvxq4M8IGCK4uX9yM3sxl1AHxw7VHf+aj9/mz:TBrlANFJ85qJvW3sxl1T/+w9/4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2934:RAhMCEAGCQCACAAAAAgQAAAAlCGJASAAQMAAQAhAAAAADCAAQAAQgEAAoBKKAAAAAgAAAgAQSAgQGiCADAIAIAEAAABAIAAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7e7e7ffff
Perceptual Hash:e6cc9933cc8c3366
Difference Hash:304c4d4d4d4d4c30
Wavelet Hash:e0e0c0c0c3c3c3c3
Color Hash:#783f3a

Scan History

Scan history not available

Unable to load historical scan data