Security Scan Report: bnimail-owa.vercel.app

Submitted: Sep 20, 2026, 3:50:02 AMCompleted: Sep 20, 2026, 3:50:21 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Outlook credential-phishing page on a vercel.app subdomain; its login form exfiltrates usernames and passwords to an external submit-form.com endpoint. Do not enter credentials.

Risk Factors
Brand impersonation of Microsoft Outlook on a non-Microsoft domain
Credential (username + password) form posting to an external cross-origin endpoint (submit-form.com)
Threat-intel phishing report on the primary domain
IDS HIGH alert for landing-page form exfiltration
Subdomain created on an actor-abused cloud hosting platform (vercel.app) with unknown age
Domain age information unavailable

Details

Page Title

BNI Outlook

Scan Type

public

Domain Name Analysis

Domain 'bnimail-owa.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'bnimail-owa'. Count 6 characters in 'vercel' with 2 vowels and four consonants. Breaking it apart gives 2 words: ver, cel. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bnimail-owa.vercel.app/

Page Load Overview

0.26s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:544 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software83% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
83%
documentation technical
81%
government public service
67%
news media journalism
66%
healthcare medical
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
064.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
34--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T121439E3FA9572C332827607463EBB28A3B2AC417864ED924387C1758EF41D76417EBD9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:gyDwuJmtz7e05Nnfvi2aD2xUkzdKV7aQblNoJmgK4e2FuzqQnclYtcY:ytzK05N7aD2xUEkF5F4nFuVcScY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57527:KeEKQI1AVgJAYCgiXggMQqIHEAAEpJgI+4IOBQWNmKGwASCfBA5FQRoe6oPgJAADw1C6yKKYg+DCFoAagwoEiYTBSIxSCKRE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd0d8d0d0d0
Wavelet Hash:3f273f3f3f000000
Color Hash:#d2797e

Scan History

Scan history not available

Unable to load historical scan data