Security Scan Report: xfinityupdates.vercel.app

Submitted: Sep 30, 2026, 2:50:26 PMCompleted: Sep 30, 2026, 2:51:09 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Fake Xfinity/Comcast sign-in page on a free vercel.app subdomain that harvests Xfinity ID and password, corroborated by multi-source phishing threat intel. Do not enter credentials.

Risk Factors (6)
Brand impersonation of Xfinity (Comcast) on a domain that is not xfinity.com
Credential capture form with password field soliciting an 'Xfinity ID'
Multi-source phishing threat-intel match on the primary domain
Unranked in Cisco Umbrella top 1M while claiming a major telecom brand
Lure: 'Let's cut your mobile bill in half' — savings bait typical of carrier-phishing kits
Single-source 'known attacker' URL indicator (generic abuse reputation)
Domain age information unavailable

Details

Page Title

xfinity

Scan Type

public

Domain Name Analysis

The domain 'xfinityupdates.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'xfinityupdates'. The registrable portion 'vercel' spans 6 characters holding 2 vowels versus four consonants. Word splitting yields 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://xfinityupdates.vercel.app/

Page Load Overview

7.92s
Total Load Time
491 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:676 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking60% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
60%
government public service
56%
technology software
47%
news media journalism
41%
adult content
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
464.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1172.67.68.11Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.217.208.95Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.26.2.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
118--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T179A2D75E32A1043A6D53C4F2F6D1BB183525A0C3DE2FC569BA9D4500AFD7AA38DA3748

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ihnOx9VrLAmJH7JXeS7JXex/27x/ZsfedNvdBwsfFf6ModGo1LkLEGoYq5m1lWkc:iFyhL71dF1f6MvykLTBq5m+kd8V

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21721:RVkUStE6qHCqAtAAtFAQAKAYtBkZRwjniYUoRAQYSAYnMQW2kIgkoEEFCPWJSCAXATAgkCaWmRuQChSqRVBhVAHgAWhBAAQA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f97ff939f9f9f9f9
Perceptual Hash:cb94f4e80f0ff0e0
Difference Hash:c3c36363630303c3
Wavelet Hash:f878f818f0f0f0f0
Color Hash:#865c2d

Scan History

Scan history not available

Unable to load historical scan data