Security Scan Report: confirm-address-changing.vercel.app

Site favicon
Submitted: Jul 9, 2026, 7:51:20 PMCompleted: Jul 9, 2026, 7:53:35 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 2 domains to perform 12 HTTP transactions. The main domain is confirm-address-changing.vercel.app and was registered NaN years ago.

Submitted URL: https://confirm-address-changing.vercel.app/landing/

AI Security Verdict

Moderate Risk

Confidence: 85%

5
Risk Score

The page impersonates DHL Express, uses a malicious IP and heavily obfuscated JavaScript, indicating a high‑risk brand‑impersonation scam.

Risk Factors
Known malicious IP associated with the site
Brand impersonation on a hosting‑platform subdomain
Unranked domain with unknown creation date
Highly obfuscated JavaScript
Safety Factors
No credential or payment collection forms
No detected malware YARA patterns
No network IDS alerts
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 5
Domain age information unavailable

Details

Page Title

DHL Express | GERMANY

Scan Type

public

Language

🇺🇸

English

(52% confidence)

Category

technology software

(28%)

Domain Information

Domain 'confirm-address-changing.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'confirm-address-changing'. The second-level label 'vercel' is 6 characters long containing two vowels alongside four consonants. Splitting it apart reveals 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://confirm-address-changing.vercel.app/landing/

Page Load Overview

6.10s
Total Load Time
12
HTTP Requests
2
Domains
40 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:52%
Script Type:Latin
HTML Lang Attribute:de
Text Length:3,405 chars
Detector Agreement:100%
Language mismatch: Declared as de but detected as en

Website Classification

Primary Category

technology software28% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
28%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
464.29.17.67United States
AS16509Amazon.com, Inc.
4216.198.79.67United States
AS16509Amazon.com, Inc.
478.46.254.202Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
123--

Page Statistics

12
Requests
2
Unique Domains
339.8 KB
Total Size

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D113193660AC113E617B15D5B0B6AF1E72B59107EA4728B0F6FC27E49FCBCD0A923644

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:WRVlZxtVpJMj93biIsiyT6Jtqc49sxIW5h7078cI2zIUkIKMIkMd8U8+uq9kdM3n:WRVlZxtVpJMj93buiCsxIWVcIWI1I1In

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:43270:O6IIMZ/4pcQAgrAbMoCQIABQAoEUHCgGFhwQBUjxCTlGAgMFeEtCiZUCUAgFBWBJECAJU2JgGHdEIcQOiQuIARBhOWCAEUUA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffcfffc3c3
Perceptual Hash:b5df241c1e24cf34
Difference Hash:3a8e488e9e609696
Wavelet Hash:00c6e6c6c6dfc3c3
Color Hash:#d279c3

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data