Security Scan Report: ar24-sigma.vercel.app

Submitted: Sep 26, 2026, 8:50:13 AMCompleted: Sep 26, 2026, 8:50:52 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed phishing kit impersonating AR24 on vercel.app: a fake login form whose email/password are exfiltrated to Telegram via sendToTelegram(), with DevTools blocking and a multi-source phishing Indicators of Compromise match.

Risk Factors (5)
Brand impersonation of AR24 on a non-official vercel.app subdomain of unknown creation date
Credential exfiltration of email/password to an external Telegram endpoint
DevTools and right-click blocking used to hinder analysis
Multi-source corroborated phishing threat-intelligence match on the primary domain
Abused cloud hosting platform (vercel.app) used to host the phishing page
Domain age information unavailable

Details

Page Title

Connexion - AR24

Scan Type

public

Domain Name Analysis

You're looking at domain 'ar24-sigma.vercel.app' on the application-focused generic top-level domain (.app) and includes subdomain 'ar24-sigma'. Its registrable label 'vercel' stretches across 6 characters holding 2 vowels versus 4 consonants. Splitting it apart reveals 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ar24-sigma.vercel.app/

Page Load Overview

3.99s
Total Load Time
61 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:1,386 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical65% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
65%
government public service
62%
download file sharing
53%
corporate business
42%
blog personal website
36%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.183.140.161France
AS211068AR24 SAS
1104.237.62.213El Segundo, California, United States
AS18450WebNX, Inc.
1149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.183.140.162France
AS211068AR24 SAS
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
107--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15FB2F91228F31D2659A7D1A63B9353C63021D003A517CA84B6DD33A58FCFE968E637DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:1d5cNG8u2N/xNzwBikjzgJWBJ1nU1Yae1bSf3ylGIddwypNB5:9/rM/xZYzgJWhnSYaybSf3yvwg

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24593:yJZZ1bmIjaSAKJBYOBChKHQEgRIqAnBAIIiBgFqRDQioHgiaH3ghhAEAYzEBAIEMBZRBo7EAUZAtE6pSQRtAAwihsHEHAlNo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe6e6fee6e67f3e
Perceptual Hash:f7aa54a2dc88d6a2
Difference Hash:684c0a324a4ad4e0
Wavelet Hash:ff02243c2424fe3e
Color Hash:#5c2d86

Other Hashes

Crop Resistant:684c0a324a4ad4e0

Scan History

Scan history not available

Unable to load historical scan data