Security Scan Report: eng-2-weld.vercel.app

Submitted: Sep 15, 2026, 12:45:11 AMCompleted: Sep 15, 2026, 12:45:37 AMpubliccompleted

Summary

This website contacted 8 IPs in 1 country across 7 domains to perform 4 HTTP transactions. The main domain is eng-2-weld.vercel.app and was registered 10 years ago.

Submitted URL: https://eng-2-weld.vercel.app/

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Fake 'Web Mail' login page on a vercel.app subdomain. A CRITICAL YARA phishing-kit signature (Telegram credential exfiltration), a HIGH ET PHISHING IDS alert, and a password-harvesting form confirm credential phishing.

Risk Factors
Known phishing-kit YARA signature (Okta phishing kit with Telegram exfiltration) present
Harvests email + password on a non-official, throwaway hosting subdomain
Vercel.app abuse-associated hosting used for a fake webmail login
ET PHISHING IDS alert for webmail phishing landing
Cross-origin POST to ipinfo.io typical of kit geolocation checks
Domain age information unavailable

Details

Page Title

Web Mail

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(48%)

Domain Information

The domain 'eng-2-weld.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'eng-2-weld'. Count 6 characters in 'vercel' holding 2 vowels versus 4 consonants. Segmentation suggests two words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://eng-2-weld.vercel.app/

Page Load Overview

7.21s
Total Load Time
10
HTTP Requests
7
Domains
173 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:98 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical48% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
48%
finance banking
45%
news media journalism
41%
adult content
35%
phishing scam
35%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3142.251.14.95Google · CDNUnited States
AS15169Google LLC
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1100.56.96.63Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
108--

Page Statistics

10
Requests
7
Unique Domains
200.2 KB
Total Size

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B6E020879DE4C81F11B08946BCE1F07D5CB4B91BB7408CDDBCE401640F647D544D7858

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:q9hqIY7YvfAbpli7vkqH8JLBpWYzvlHT8NWQAlKPUQyrNVTvxMjNVuB9d:njy7SdWYz9z8NWQCUURNVTJMjNVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:942900838abea51724d7a8ed36b04a99

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffbd3c3c00000000
Perceptual Hash:88cdcf7332666631
Difference Hash:717171711db10195
Wavelet Hash:ffffffff00000000
Color Hash:#e0a66c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data