Security Scan Report: protocol-node.vercel.app

Submitted: Sep 18, 2026, 11:47:29 PMCompleted: Sep 18, 2026, 11:47:48 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Free vercel.app page mimicking a wallet 'validation/migration/claim rewards' service, matching a single-source wallet-drainer phishing report. Do not connect a wallet or submit details.

Risk Factors (5)
Single-source wallet-drainer IoC on the primary domain (content-malware class)
'Wallet validation / migration / claim rewards' phrasing is the standard crypto-phishing lure
Unranked, free hosting-platform subdomain with unknown creation date
IDS alerts for actor-abused cloud hosting (vercel.app)
Requests wallet connection and user KYC/wallet details with no verifiable operator or trust signals
Domain age information unavailable

Details

Page Title

Protocol Node

Scan Type

public

Domain Name Analysis

Domain 'protocol-node.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'protocol-node'. The core label 'vercel' covers 6 characters containing two vowels alongside 4 consonants. Splitting it apart reveals 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://protocol-node.vercel.app

Page Load Overview

1.41s
Total Load Time
335 KB
Total Size

Language Analysis

Primary Language

馃嚭馃嚫English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,282 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software73% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
73%
cryptocurrency blockchain
53%
documentation technical
53%
finance banking
30%
government public service
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
764.29.17.67Aws 路 CLOUDUnited States
AS16509Amazon.com, Inc.
2142.251.14.95Google 路 CDNUnited States
AS15169Google LLC
2104.17.208.5Cloudflare 路 WAFUnited States
AS13335Cloudflare, Inc.
2216.198.79.195Aws 路 CLOUDUnited States
AS16509Amazon.com, Inc.
2142.250.154.95Google 路 CDNUnited States
AS15169Google LLC
264.29.17.195Aws 路 CLOUDUnited States
AS16509Amazon.com, Inc.
2142.251.14.94Google 路 CDNUnited States
AS15169Google LLC
197--

Detected Technologies4

JQueryv3.6.0
100%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B242415BA9F32546A503E0B0ABB2D7A777189403D10AC9747FBC51A8DF4DBC08993B8D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:GM0q0c6goWNcfnrh5v2CXEaN4xBqK4ha/ciPgONcXGmRPeaJzvBRJ3aovTf/CTml:GsJqt0qZDCyjJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12357:J6GBAAAoiMISkJEKAkASUYCsAGHFKoIgC8wVmRxREKkw44RSGiLiCSHDoxApEESzESKIAnPDME5CFgUDUBKHKSAjmQQQJKoA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:81183d3d010138ff
Perceptual Hash:8a5da232aa0b8f5f
Difference Hash:2171717161416961
Wavelet Hash:813d3d3d01013dff
Color Hash:#405bbf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data