Security Scan Report: orange-1.vercel.app

Submitted: Sep 23, 2026, 9:51:51 AMCompleted: Sep 23, 2026, 9:52:23 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 98%

10
Risk Score

Confirmed Orange credential-phishing page on a vercel.app subdomain: fake CAPTCHA lure, disguised password field, and JavaScript exfiltrating email/password to Telegram. Safe Browsing flags Social Engineering.

Risk Factors (8)
Brand impersonation of Orange on a non-official vercel.app subdomain
Credential harvesting form (email/mobile + password) combined with the Orange brand
JavaScript sends captured credentials to an external Telegram endpoint
Disguised password field (text input masquerading as a password field)
Unicode confusion/evasion characters in form fields
Fake CAPTCHA human-verification gate before login collection
ML content classifier labels the page 'phishing scam' (43%)
IDS alerts: DNS/TLS activity to actor-abused cloud hosting domain vercel.app
Domain age information unavailable

Details

Page Title

Vérification Orange

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'orange-1.vercel.app' is registered and includes subdomain 'orange-1'. The core label 'vercel' covers 6 characters split between two vowels and 4 consonants. Splitting it apart reveals 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://orange-1.vercel.app/

Page Load Overview

0.79s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:442 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam43% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
43%
government public service
33%
adult content
30%
technology software
28%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.251.156.119Google · CDNUnited States
AS15169Google LLC
3185.15.59.224United States
AS14907Wikimedia Foundation Inc.
3142.250.154.100Google · CDNUnited States
AS15169Google LLC
3142.251.154.119Google · CDNUnited States
AS15169Google LLC
3142.250.154.138Google · CDNUnited States
AS15169Google LLC
3142.251.20.94Google · CDNUnited States
AS15169Google LLC
3185.15.59.240United States
AS14907Wikimedia Foundation Inc.
3142.251.110.94Google · CDNUnited States
AS15169Google LLC
359--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14C62936321550C3A626386E479A6A74E3019DF17EE5BE08CB2FC939D87C6CD3993178C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:X2f0PbD7SF6ZTeNjyeW+zzxeiQn7zZsAL0pWY5fKE:QQbD7SF6ZTCFhPE+A4WY5CE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15475:KpDQmSTLEIQAdUiAV6illFAqGhAWrEIEwMAiAQEEUClBB4mNQEduuCJYgBYIGgwoUQYUshZKiBQAoTRIkqEAgeiSoK/QWzmg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:b8384743794f474e
Difference Hash:9818a8b890400000
Wavelet Hash:0000c4c4c4f4cccc
Color Hash:#2d866d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data