Security Scan Report: kjhkjh-o4ul.vercel.app

Submitted: Sep 26, 2026, 8:50:42 PMCompleted: Sep 26, 2026, 8:52:07 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Anonymous credential-capture login page on a throwaway .vercel.app subdomain with hidden kit-style fields and an IP-geolocation lookup; no legitimate site identity. Do not enter credentials.

Risk Factors (5)
Credential (email + password) capture form on an anonymous shared-hosting subdomain with no legitimate site context
Randomized subdomain and filename (kjhkjh-o4ul.vercel.app/hgcfgvgh.html) indicative of throwaway phishing infrastructure
Hidden form fields and template-style login/error strings suggestive of a ready-made phishing kit
External IP-geolocation lookup to ipinfo.io typical of kit victim-filtering
No brand, owner, or content of any kind — a bare credential page with no legitimate purpose
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Domain 'kjhkjh-o4ul.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'kjhkjh-o4ul'. The core label 'vercel' covers 6 characters split between 2 vowels and 4 consonants. Tokenizing the label suggests 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kjhkjh-o4ul.vercel.app/hgcfgvgh.html

Page Load Overview

3.06s
Total Load Time
399 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:???
Text Length:221 chars
Detector Agreement:100%
Language mismatch: Declared as ??? but detected as en

Website Classification

Primary Category

finance banking30% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
30%
adult content
30%
government public service
30%
news media journalism
30%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0142.251.20.95Google · CDNUnited States
AS15169Google LLC
0142.251.14.95Google · CDNUnited States
AS15169Google LLC
0104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.150.119Google · CDNUnited States
AS15169Google LLC
0172.67.139.119Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1518--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BF054F56AD671C890B15A07920DF2AC11B2E63DBA8468CDCB50FF7DCCFE818658E17C9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:6ApK3aZ6sKB2WXeqAlPf0msGTVXOuqs/wacSwTo7ode2JLoiuedEMSoLV:6RGPfZsEXOuqs/UrJHV

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:833018:iXBGXShrJ0AAYAFpRQGAWER0EgMAYYUJBmECGAuELhoGZLhEEQADR1TUGJyOHAgAQhBoFeQTSJNlhKoBWoyAAAAK4gNCILGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:9999666666333399
Difference Hash:4cb2b2b2b24c3000
Wavelet Hash:30383c3c1c0c0c0c
Color Hash:#79bcd2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data