Security Scan Report: oznormali.vercel.app

Submitted: Sep 19, 2026, 6:50:02 AMCompleted: Sep 19, 2026, 6:50:19 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

Fake Microsoft Outlook login on a vercel.app subdomain that harvests email and password via a cross-origin form to submit-form.com — credential phishing.

Risk Factors
Impersonation of Microsoft Outlook branding on a non-Microsoft domain (vercel.app subdomain).
Credential form (email + password) with cross-origin submission to submit-form.com — credentials leave the site.
Domain unranked in Cisco Umbrella; vercel.app subdomain creation date unknown.
Fake login filler text ('browser settings must allow scripts', 'Please enable cookies') mimicking a real Outlook error page.
Domain age information unavailable

Details

Page Title

Outlook

Scan Type

public

Domain Name Analysis

The domain name 'oznormali.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'oznormali'. Its registrable label 'vercel' stretches across 6 characters containing two vowels alongside 4 consonants. Tokenizing the label suggests two words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://oznormali.vercel.app/

Page Load Overview

0.25s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:579 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software82% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
82%
documentation technical
79%
news media journalism
67%
government public service
61%
healthcare medical
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
33--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T162439E3FA9572C332827607463DBB28A3B2AC417824ED924387C1758EF81D76417EBD9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:byDwuJmtz7e05Nnfvi2aD2x9kzdKV7aQblNoJmgK4e2FuzxQnc6YtcY:ttzK05N7aD2x9EkF5F4nFuccPcY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57563:1AFyaTo0uQQAsACAFx+jTdNOKZhIiiGEVIAJCxAOgEAwABEgmgAkAgHkDkUNwhAVEfXGUwDCAagD6NF1aHApAWAFEG4qxhtu

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd0d8d0d0d0
Wavelet Hash:3f273f3f3f000000
Color Hash:#1f4293

Scan History

Scan history not available

Unable to load historical scan data