Security Scan Report: vd4hy6lkykz7c1p1f3q.vercel.app

Redirected to:
https://vbzr87n-h20n.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 21, 2026, 12:45:09 PMCompleted: Sep 21, 2026, 12:45:29 PMpubliccompleted

This website contacted 2 IPs in 1 country across 3 domains to perform 4 HTTP transactions. The main domain is vbzr87n-h20n.vercel.app and was registered 14 years ago.

Submitted URL: https://vd4hy6lkykz7c1p1f3q.vercel.app/sdfn45wstnrefyje5hrtbw.html

Effective URL:

https://vbzr87n-h20n.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Randomly-named Vercel subdomain serving cloned content with a hidden password field that posts cross-origin to a second Vercel subdomain — credential-harvesting phishing with anti-analysis cloaking.

Risk Factors (6)
Hidden password field not visible to the user
Cross-origin credential form action to a separate random Vercel subdomain
Mirrored/cloned website (phishing IDS signature)
Cloaking / divergent content served to scanner vs. real client
External IP-lookup services used for victim profiling
Unranked, unknown-age free-hosting subdomain with machine-generated names
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'vd4hy6lkykz7c1p1f3q.vercel.app' is registered and includes subdomain 'vd4hy6lkykz7c1p1f3q'. The second-level label 'vercel' is 6 characters long holding two vowels versus 4 consonants. Breaking it apart gives two words: ver, cel. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://vd4hy6lkykz7c1p1f3q.vercel.app/sdfn45wstnrefyje5hrtbw.html

Page Load Overview

0.76s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:45%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:vi
Text Length:4,015 chars
Detector Agreement:75%
Language mismatch: Declared as vi but detected as en

Website Classification

Primary Category

social media network50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
50%
technology software
30%
documentation technical
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
264.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
42--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115A1377329E221005DEC96F568DC3B0C735EC45F0982DD67D28E283CB72FADAB499554

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F09k/N9oWUuxRk1BtG8jQ7NBp+44:TBxslWFyRk3dU2R+BtYTc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4866:4KwBABgEApJBtgKEkCGAgEBCQIIARoECEAGAAgFSCQEQIIoSAqFAAgsWCAACDCSIlEAQgJokFAAJAwAACAAlo2SFjAFDAoGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b9c6c63139cec631
Difference Hash:0000001010000000
Wavelet Hash:f0f0f0c0c0f0f0f0
Color Hash:#9940bf

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data