Security Scan Report: t2mm31k7dsuitdqhw3p.vercel.app

Redirected to:
https://pfdy11x-h20x.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 21, 2026, 12:45:12 PMCompleted: Sep 21, 2026, 12:45:33 PMpubliccompleted

This website contacted 6 IPs in 1 country across 5 domains to perform 22 HTTP transactions. The main domain is pfdy11x-h20x.vercel.app and was registered 10 years ago.

Submitted URL: https://t2mm31k7dsuitdqhw3p.vercel.app/sdfn45wstnrefyje5hrtbw.html

Effective URL:

https://pfdy11x-h20x.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 70%

7
Risk Score

Cloaked page on a vercel.app tenant: hidden password field plus credential forms posting to another random subdomain, IP-lookup cloaking and an ET PHISHING hit. Do not enter credentials.

Risk Factors (6)
Hidden password field not visible to the user
Credential-bearing forms submitting cross-origin to an unrelated random vercel.app subdomain
Cloaking / evasion: block page served to datacenter scanner, different real content served to residential client
External IP-lookup service (ipapi.co) used at page load
Thrown-together random subdomain and file names with multiple redirects
No domain reputation (unranked in Cisco Umbrella) and hosting-platform tenant of unknown true age
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

The domain 't2mm31k7dsuitdqhw3p.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 't2mm31k7dsuitdqhw3p'. The core label 'vercel' covers 6 characters holding two vowels versus 4 consonants. Word splitting yields 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://t2mm31k7dsuitdqhw3p.vercel.app/sdfn45wstnrefyje5hrtbw.html

Page Load Overview

0.30s
Total Load Time
548 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:12 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
364.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3151.101.129.229Fastly · CDNUnited States
AS54113Fastly, Inc.
3104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.21.31.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.67.180.104Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
226--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115A1377329E221005DEC96F568DC3B0C735EC45F0982DD67D28E283CB72FADAB499554

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F09k/N9oWUuxRk1BtG8jQ7NBp+44:TBxslWFyRk3dU2R+BtYTc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4866:4KwBABgEApJBtgKEkCGAgEBCQIIARoECEAGAAgFSCQEQIIoSAqFAAgsWCAACDCSIlEAQgJokFAAJAwAACAAlo2SFjAFDAoGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b9c6c63139cec631
Difference Hash:0000001010000000
Wavelet Hash:f0f0f0c0c0f0f0f0
Color Hash:#ac6553

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data