Security Scan Report: erwi.vercel.app

Redirected to:
https://erwi.vercel.app/
Submitted: Sep 15, 2026, 12:45:09 AMCompleted: Sep 15, 2026, 12:45:32 AMpubliccompleted

This website contacted 8 IPs in 1 country across 7 domains to perform 11 HTTP transactions. The main domain is erwi.vercel.app and was registered 23 years ago.

Submitted URL: http://erwi.vercel.app/

Effective URL:

https://erwi.vercel.app/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Pseudo 'example.com mail authentication' portal on a free vercel.app subdomain that collects email and password; template phishing kit with IP-lookup callbacks. Do not enter credentials.

Risk Factors
Credential harvesting form (email + password) on a domain unrelated to the brand it claims to represent
Impersonation of example.com mail authentication on erwi.vercel.app
Cross-origin IP geolocation callbacks (ipapi.co, api.ipify.org) from page scripts
Obfuscated/encoding inline JavaScript with network sinks
Unknown subdomain creation date on abused free-hosting platform; domain unranked in Cisco Umbrella
Domain age information unavailable

Details

Page Title

PORTAL - example.com Mail Authentication

Scan Type

public

Domain Name Analysis

You're looking at domain 'erwi.vercel.app' on the application-focused generic top-level domain (.app); it also runs on subdomain 'erwi'. The core label 'vercel' covers 6 characters containing two vowels alongside 4 consonants. Breaking it apart gives 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://erwi.vercel.app/

Page Load Overview

5.55s
Total Load Time
240 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:401 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software75% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
75%
government public service
31%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.152.119Google · CDNUnited States
AS15169Google LLC
132.199.23.92Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1142.251.20.105Google · CDNUnited States
AS15169Google LLC
118--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T178A2D75A09F30021B523E1783FFB53083671800B9606DD28B95C5394DFC8DA26ABFBE9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:d8BIGRLRNm69g1vr1ntjbTe5VcQ2PBKemGOdDT5ghwhmVutAoSuCIdtLrJKRwq1l:mBIBfVKDEoX4sGMflldD+3P2bsmQf2OR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21515:CUEJoDicZAwCQ1ABFDFUAQwUe0JOkDAZTKAAwiSSoaIAAKQNRCURASFVkg4QgFD0gCIRnHpPABaCA0RxEEEcDJoAQihmKIKY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000001818000000
Perceptual Hash:9c3c36c1c9c36765
Difference Hash:10322eb2b20c0000
Wavelet Hash:3f01013f1c040000
Color Hash:#3a4978

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data