Security Scan Report: xatho5vqsukenlxz7pr.vercel.app

Redirected to:
https://ibbx15706-h25.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.htm...
Submitted: Sep 28, 2026, 12:45:18 AMCompleted: Sep 28, 2026, 12:46:42 AMpubliccompleted

This website contacted 9 IPs in 1 country across 5 domains to perform 21 HTTP transactions. The main domain is ibbx15706-h25.vercel.app and was registered 10 years ago.

Submitted URL: https://xatho5vqsukenlxz7pr.vercel.app/fsmn345rnefdzbxcq2vxthy

Effective URL:

https://ibbx15706-h25.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.htm...
Redirected

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Near-empty credentials page on chained random Vercel subdomains with a hidden password field and content cloaking — phishing-kit characteristics. Do not enter any login or personal data.

Risk Factors (5)
Hidden password field in DOM not visible to the user
Random, non-descriptive subdomains on a free hosting platform used to chain redirects
Near-blank landing page that loads its real content only for certain clients (cloaking)
Credential fields with no visible legitimate login context on the page
External IP-geolocation lookup (ipapi.co) consistent with visitor-fingerprinting/cloaking logic
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

The domain name 'xatho5vqsukenlxz7pr.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'xatho5vqsukenlxz7pr'. Count 6 characters in 'vercel' split between two vowels and four consonants. Splitting it apart reveals 2 words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://xatho5vqsukenlxz7pr.vercel.app/fsmn345rnefdzbxcq2vxthy

Page Load Overview

15.61s
Total Load Time
549 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:12 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
264.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.180.104Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
264.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.21.31.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
219--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T187A1D4E32DC18D45A9C89CC483DD7D18635AFE9A99813D63B2C7205D9F17EDEB428288

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6FxWQ8roglD3PSMmpmLiJd5h3ccp+43P:TBxslWFyRkQQXgVLcRc4/

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5065:SIQRAAgUA5eS+gCQgCGAEQgqCAYAUCAAiAQABmBwKEAoQIoEUQBAA1AUAgACgCUApBJBBTOgHAAAogAxKsAuJ2UApAECAAAR

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffff
Perceptual Hash:e699992666999966
Difference Hash:0000000808000000
Wavelet Hash:3c3c3c24273f0f0f
Color Hash:#8790c5

Other Hashes

Crop Resistant:0000000808000000

Scan History

Scan history not available

Unable to load historical scan data