Security Scan Report: xbu55.vercel.app

Redirected to:
https://xbu55.vercel.app/
Site favicon
Submitted: Sep 17, 2026, 1:45:44 PMCompleted: Sep 17, 2026, 1:46:50 PMpubliccompleted

This website contacted 3 IPs in 1 country across 3 domains to perform 20 HTTP transactions. The main domain is xbu55.vercel.app and was registered 2 months ago.

Submitted URL: http://xbu55.vercel.app/

Effective URL:

https://xbu55.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Cloned Microsoft login page on a Vercel subdomain with Microsoft's favicon and $Config schema, harvesting credentials to an external host (login.coachjosuecosta.com); flagged by Safe Browsing for social engineering. Confirmed phishing.

Risk Factors
Cloned Microsoft sign-in page hosted on a shared Vercel subdomain with a hidden cross-origin form action
Microsoft favicon and login $Config schema on a domain that is not Microsoft's
Credential form submits to an unrelated external host (login.coachjosuecosta.com)
DevTools and right-click blocking to obstruct inspection
Google Safe Browsing Social Engineering threat reported
Network IDS high alert: ET DROP Spamhaus DROP listed traffic inbound
Domain age information unavailable

Details

Page Title

Filessecondary capture

Scan Type

public

Domain Name Analysis

Domain 'xbu55.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'xbu55'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus four consonants. It segments into 2 words: ver, cel. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://xbu55.vercel.app/

Page Load Overview

6.00s
Total Load Time
251 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:105 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software77% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
77%
documentation technical
74%
download file sharing
66%
healthcare medical
66%
adult content
47%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
6216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
664.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
203--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T175F19434E556F6BF8523CDD5E832737E548BA2CDD5A1490CB3FC826813A2C898C66C89

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:alVvZuzUn9xaxIQxjyOXOYQOxlLU6+roSMLtRC7PxtJz:4Tug/qIwJeYrxlLUH4LS7PxtJz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8001:GODaBQggJBJQBOwWgjytASgjIojAkIC4ADAQ2MACsJAANClAJHWhVAhwFgoNJFZMSqJER1Ah2RDBtYMQUEAkIIiQzQF4Q0OQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e3ff8181bfffff
Perceptual Hash:ff60405f4b591b62
Difference Hash:50060e2b2b710421
Wavelet Hash:00c3c7818189ffff
Color Hash:#aad279

Scan History

Scan history not available

Unable to load historical scan data