Security Scan Report: xej55ayx90zmm6blgnf.vercel.app

Redirected to:
https://awzh49e-h09e.vercel.app/10004567348379/fbs5wsertnbstfdg4scxqIB...
Submitted: Sep 14, 2026, 12:45:03 AMCompleted: Sep 14, 2026, 12:45:28 AMpubliccompleted

This website contacted 2 IPs in 1 country across 3 domains to perform 3 HTTP transactions. The main domain is awzh49e-h09e.vercel.app and was registered 14 years ago.

Submitted URL: https://xej55ayx90zmm6blgnf.vercel.app/gsnfns43e5rhbwaerdfsvb

Effective URL:

https://awzh49e-h09e.vercel.app/10004567348379/fbs5wsertnbstfdg4scxqIB...
Redirected

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Content-free Vercel subdomain serving 3 forms including a hidden password field, posting credentials cross-origin, with a mirrored-website phishing IDS signature. No Indicators of Compromise or malware, but credential harvesting shape is clear — avoid entering any data.

Risk Factors
Password field present in the DOM but not visible to the user (hidden credential input)
3 forms / 7 email-or-username fields on a page with no rendered content
Machine-generated subdomain and file path with no branding or purpose
Cross-origin form submission to a second randomised vercel.app subdomain
Phishing-specific IDS signature (mirrored-website phish) present
Hosting namespace flagged by IDS as commonly actor-abused
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

You're looking at domain 'xej55ayx90zmm6blgnf.vercel.app' on the application-focused generic top-level domain (.app) and includes subdomain 'xej55ayx90zmm6blgnf'. The registrable portion 'vercel' spans 6 characters with two vowels and four consonants. Splitting it apart reveals 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://xej55ayx90zmm6blgnf.vercel.app/gsnfns43e5rhbwaerdfsvb

Page Load Overview

0.29s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:45%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:vi
Text Length:4,015 chars
Detector Agreement:75%
Language mismatch: Declared as vi but detected as en

Website Classification

Primary Category

social media network53% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
53%
technology software
30%
documentation technical
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
264.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
32--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T193C167739CD8DC1465F6C69958CC3E08FA17952B89499D23F2C7222C5B9B9DEF038E18

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TBxslWLkXPLvu6whAq5/7tRjIUJ8Hx5wRpCL5hus3eWlB1kp+K/82BpPWFKpPDYZ:VxslWLkXDu6whAq5/7tRjIU+Hx50pCLh

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5665:AQGJAJAEBDCQkkEYsIQAK4iAFAAXEEwCQo+AgAVACRIIk0BUBDGSAZBZGTCjAJQAECMBgEIJgEICsoEhCQBgIKSBtEoIAUAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b1c6ce3131cece31
Difference Hash:0000001818000000
Wavelet Hash:f0f0f0c0c0f0f0f0
Color Hash:#6ce0dc

Other Hashes

Crop Resistant:0000001818000000

Scan History

Scan history not available

Unable to load historical scan data