Security Scan Report: upgraded-eth.vercel.app

Submitted: Sep 27, 2026, 12:45:01 PMCompleted: Sep 27, 2026, 12:46:51 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake 'Trust Wallet' transfer page on a vercel.app subdomain that shows an attacker crypto address and reports to Telegram — a crypto drainer impersonating a real wallet brand. Do not send funds.

Risk Factors (6)
Impersonation of the Trust Wallet brand on a non-official domain
Hardcoded crypto recipient address in a fake transfer form (wallet-drainer pattern)
Outbound connection to Telegram Bot API endpoint consistent with exfiltration/attacker notification
IP-address harvesting via api.ipify.org
Abused cloud-hosting subdomain (IDS ET TA_ABUSED_SERVICES on vercel.app) with unknown page age
Unranked domain presenting itself as a major crypto wallet brand
Domain age information unavailable

Details

Page Title

Trust Wallet

Scan Type

public

Domain Name Analysis

The domain 'upgraded-eth.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'upgraded-eth'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus 4 consonants. Tokenizing the label suggests 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://upgraded-eth.vercel.app/

Page Load Overview

75.28s
Total Load Time
802 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:64 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking81% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
81%
cryptocurrency blockchain
42%
healthcare medical
38%
news media journalism
27%
adult content
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
77216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
75172.67.70.222Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
75104.26.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
75149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
75216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
7564.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
75104.26.14.209Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
75104.26.15.209Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6028--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10FD172A4F8E11A221343007579E3BA6B7E3DD507D28EAD0439DC92F51FE3D818A6B45B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:5H/vWqr3uuau9WCWaJ9mkow/Lq3ZWHE5xy/AM5ge/5zM4+FgEr5XXSyv55wMnhHz:5fvWqLuuau9WCWaJAkow/L4WHr/oV7vF

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6753:vVgIAigJAMKJoRkDDATQYBhFAA1EAASDKARKAIG0wIIKpwwJUAIgQ1gIggJq8kAkhSJQkBBDSHopMIAQEAAFEyYzBAAIosIw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1818181818181818
Perceptual Hash:cccc33339973cc64
Difference Hash:b2b2b2b2b2b2b2b2
Wavelet Hash:1c1c18183c3c1c1c
Color Hash:#87a8c5

Scan History

Scan history not available

Unable to load historical scan data