Security Scan Report: ctmscat.vercel.app

Redirected to:
https://ctmscat.vercel.app/
Submitted: Sep 29, 2026, 12:45:05 AMCompleted: Sep 29, 2026, 12:45:45 AMpubliccompleted

This website contacted 4 IPs in 1 country across 2 domains to perform 4 HTTP transactions. The main domain is ctmscat.vercel.app and was registered 18 years ago.

Submitted URL: http://ctmscat.vercel.app/

Effective URL:

https://ctmscat.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Phishing page impersonating the Generalitat de Catalunya on a vercel.app subdomain; its sign-in form exfiltrates email and password to submit-form.com. Do not enter credentials.

Risk Factors (4)
Brand impersonation of a government entity (Generalitat de Catalunya) on a mismatched host
Login form collecting email and password submitted to an external form-relay service (submit-form.com)
Subdomain on free hosting platform (.vercel.app) with unknown creation date
HIGH-severity IDS alert for form exfiltration to submit-form.com; two MEDIUM alerts for actor-abused cloud hosting (vercel.app)
Domain age information unavailable

Details

Page Title

Generalitat de Catalunya - Sign in

Scan Type

public

Domain Name Analysis

The domain 'ctmscat.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'ctmscat'. The second-level label 'vercel' is 6 characters long containing 2 vowels alongside 4 consonants. Breaking it apart gives two words: ver, cel. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://ctmscat.vercel.app/

Page Load Overview

0.24s
Total Load Time
9 KB
Total Size

Language Analysis

Primary Language

🇪🇸CA
Code: ca
Confidence:34%
Script:Unknown
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:289 chars
Detector Agreement:75%
Language mismatch: Declared as en but detected as ca

Website Classification

Primary Category

government public service64% confidence
Type: webapp
Method: ml+structural

All Detected Categories

government public service
64%
corporate business
61%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
164.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.14.139Google · CDNUnited States
AS15169Google LLC
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.13.100Google · CDNUnited States
AS15169Google LLC
44--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19361115686A3098BB803A4742FFB93263124C063864ADE383F9C675CDF8D6D1C92379C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:ThKWtqOG+EW6OGzFOGkuCZOGpOGAkuOGIOGKOGwxOG++vYVX8nlHIG7JPUHxUsR+:ThKWn+yj5NXvRnlLP1q+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3222:YA4BQBEA4AEAAIiAMIIgEAAQAQCYAABAAAQAAgAAAAqAAEAIAAEmMICAAEZAoAAAAAuAgAAAAcAYAoAiAIAAAgAEAXACQSQI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181800
Perceptual Hash:99dd267722d98866
Difference Hash:4c32b2b2b2b2b24d
Wavelet Hash:0c1c3c3c3c3c1c0d
Color Hash:#936b1f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data