Security Scan Report: levoretsv.vercel.app

Redirected to:
https://levoretsv.vercel.app/index.html?lang=de
Submitted: Sep 28, 2026, 12:45:04 PMCompleted: Sep 28, 2026, 12:45:36 PMpubliccompleted

This website contacted 6 IPs in 3 countries across 2 domains to perform 12 HTTP transactions. The main domain is levoretsv.vercel.app and was registered 4 years 8 months ago.

Submitted URL: https://levoretsv.vercel.app/

Effective URL:

https://levoretsv.vercel.app/index.html?lang=de
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Facebook credential-phishing page on a vercel.app subdomain: fake login-alert lure plus forms capturing current password, new password and 2FA codes, with IP-geolocation scripts. Report and do not enter any data.

Risk Factors (5)
Facebook brand impersonation on a non-official domain (levoretsv.vercel.app)
Credential-capture flow collecting current password, new password and 2FA/confirmation codes
Urgent account-compromise scare language ('Om det inte var du...' / 'Jemand hat sich gerade in dein Facebook-Konto eingeloggt')
IP-geolocation lookups (ipwho.is, api.ipapi.is, ipapi.co) used to fabricate a location-based login alert
Subdomain on a shared hosting platform where creation date is unknown and cannot be trusted
Domain age information unavailable

Details

Page Title

Facebook

Scan Type

public

Domain Name Analysis

You're looking at domain 'levoretsv.vercel.app' on the application-focused generic top-level domain (.app), featuring subdomain 'levoretsv'. The second-level label 'vercel' is 6 characters long with 2 vowels and four consonants. Breaking it apart gives two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://levoretsv.vercel.app/

Page Load Overview

0.33s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:51%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,735 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as de

Website Classification

Primary Category

social media network99% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
99%
technology software
83%
blog personal website
77%
education learning
72%
news media journalism
71%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2104.20.44.133Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2167.233.217.29Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
2188.68.242.180Olsztyn, Warmia-Masuria, Poland
AS197226sprint S.A.
264.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2172.66.175.107Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
126--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T162F22A65B0A4163EE6FB1AE860A707983439D10AFC824045BDBF5E28D596CC77933BDC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:NgDb33Wsuawznevtzczu8kKunWQ+umuP0mSbqqyoQOT1vCbvs6vJEBLwaVYGn5o3:riv+45zaVt5zon

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:34281:QAAFfhRQLoI9FnAklwpDhyQIEUDswAlwGgSAQcEYIgBFARwyCY3BDBpQAQcqGMiwF4hgkAIQEoEAit0poHQkOgzgTA4VlgxK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00fffff3ffffffff
Perceptual Hash:ec591b5a6c643333
Difference Hash:20d8587604000000
Wavelet Hash:00bcccf003273f3f
Color Hash:#5b3a78

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data