Security Scan Report: horame.vercel.app

Site favicon
Submitted: Sep 26, 2026, 4:50:32 PMCompleted: Sep 26, 2026, 4:52:20 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 85%

3
Risk Score

Discord-branded login page served on a non-Discord Vercel subdomain. Meta tags and the on-screen login UI impersonate Discord to collect credentials — a phishing clone. Avoid entering any credentials.

Risk Factors (5)
Impersonation of a different entity's brand (Discord) on a non-Discord domain
Discord-lookalike credential/ login interface presented to users on a Vercel subdomain
Unknown page age on shared hosting platform — subdomain could have been created minutes ago
Unranked domain with no reputation
Network IDS observed DNS/TLS traffic to an actor-abused cloud hosting service domain
Safety Factors (5)
No JavaScript malware (YARA) hits
No Indicators of Compromise matching the page or its loaded resources
No cross-origin credential exfiltration observed in the analyzed JavaScript
No payment fields detected
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 3
Domain age information unavailable

Details

Page Title

Discordsecondary capture

Scan Type

public

Domain Name Analysis

The domain name 'horame.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'horame'. The second-level label 'vercel' is 6 characters long split between two vowels and 4 consonants. Breaking it apart gives 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://horame.vercel.app/

Page Load Overview

8.82s
Total Load Time
3.6 MB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Text Length:7 chars
Detector Agreement:0%

Website Classification

Primary Category

corporate50% confidence
Type: dynamic
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
364.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
72--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19C334330C16D689B865A4A1F7147F2E5F50F024E7BC1CE68544E4E5F2AC9DEE383262B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:WIHqM/uR9AZvNO1BtEvWPpWwZvNXA5VgIeFx/w:WzM/NZvNPuWwZvNX4SIeFx/w

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:52772:ACIEIGfwaOWQAByAZkSBD5CMkmQ0CGZWZiWD14EBBAERHCOqiiAIXIKJDIsk8KIhBsUiIBoiYgAEGQDOwNFIJaE6CM3IA1MA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1f0f17031f130307
Perceptual Hash:aed7b11a9b78cc02
Difference Hash:7fef672bebe79fff
Wavelet Hash:1f0f178f1f130707
Color Hash:#6ce0ad

Other Hashes

Crop Resistant:7fef672bebe79fff

Scan History

Scan history not available

Unable to load historical scan data