Security Scan Report: merrill-edge.vercel.app

Site favicon
Submitted: Sep 24, 2026, 1:45:16 PMCompleted: Sep 24, 2026, 1:46:05 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Phishing page impersonating Merrill Lynch / Bank of America on merrill-edge.vercel.app; its fake banking login form submits passwords off-site to formsubmit.co ([email protected]). Safe Browsing Social Engineering hit.

Risk Factors (6)
Safe Browsing Social Engineering detection
Brand impersonation of Merrill Lynch / Bank of America on a non-official domain
Credential-harvesting login form (password field) on a brand-impersonating page
Cross-origin credential submission to formsubmit.co / [email protected] (credential exfiltration)
Hosting-platform subdomain (vercel.app) with unknown page age and no domain reputation
Network IDS flagged DNS/TLS traffic to the commonly actor-abused cloud hosting service domain vercel.app
Domain age information unavailable

Details

Page Title

Log In to Merrill Lynch Online

Scan Type

public

Domain Name Analysis

The domain name 'merrill-edge.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'merrill-edge'. Count 6 characters in 'vercel' split between 2 vowels and 4 consonants. Splitting it apart reveals two words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://merrill-edge.vercel.app/

Page Load Overview

7.84s
Total Load Time
2.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:18,127 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking85% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
85%
technology software
56%
documentation technical
46%
government public service
40%
corporate business
39%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
18216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1764.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
352--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13FB48536F1F2437A85AE7654F26177847153D70BBBA32BFEF00C82A40B89A994D1359C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:+rQ4mRrfnHmVl+NzU/XRBFYy84mRrfnHmVAR:cQ4mRrfnHmVl+NzU/XRBFYy84mRrfnHH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:530745:iQg8IDRRmFTMAIYhISAzYoSErEVCioFGCSCtYGBFiaCDUhBBZomIHVQMAJEwRakyDJAEko462BsRqFBgQjirmAFMYwJgxtiA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c1c1c1c181ffffff
Perceptual Hash:eb6b949c3c94941e
Difference Hash:1b131f1f1f6dcc13
Wavelet Hash:8181818181ffe7ff
Color Hash:#93401f

Scan History

Scan history not available

Unable to load historical scan data