Security Scan Report: metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app

Redirected to:
https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/evm/
Site favicon
Submitted: Aug 13, 2026, 2:45:28 PMCompleted: Aug 13, 2026, 2:48:20 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 4 domains to perform 2 HTTP transactions. The main domain is metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app and was registered NaN years ago.

Submitted URL: http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/evm

Effective URL: https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/evm/Redirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

The site hosts highly obfuscated JavaScript with a confirmed WebSocket C2 pattern and Safe Browsing social‑engineering flag, indicating malware distribution risk.

Risk Factors
High‑severity WebSocket command‑and‑control pattern
Social engineering Safe Browsing alert
Heavy JS obfuscation and encoded payloads
Phishing indicator IoCs (even if single‑source)
Subdomain on Vercel hosting with unknown creation date
Domain age information unavailable

Details

Page Title

Connect to EVM networks | MetaMask developer documentation

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(96%)

Domain Information

The domain name 'metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'metamask-docs-l8lvh00ol-consensys-ddffed67'. The registrable portion 'vercel' spans 6 characters with two vowels and four consonants. It segments into two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/evm

Page Load Overview

8.89s
Total Load Time
22
HTTP Requests
4
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,483 chars
Detector Agreement:80%

Website Classification

Primary Category

technology software96% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
96%
documentation technical
83%
corporate
35%
cryptocurrency blockchain
28%
cryptocurrency
22%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
5216.198.79.67United States
AS16509Amazon.com, Inc.
564.239.123.193United States
AS16509Amazon.com, Inc.
518.245.31.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
224--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T129E31732E1D0203F9917439EDB90AB28727BD4DBDA8E22E1B35C866047C3BD6651787D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:yyhv9iNntPosgumqm489R+ri9lOogTs9/Hj99sviSSa9EGrqOwz7YeKeOemeqeql:ydNntPosgumqmITs9Pj99slV

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:143457:RCTF20REqgJhGIboA18KUKyEDaJKOIIcrYZiBSBqLwAJFgAgB5ARLgHEMcgxlhEhByAsAjmBUskAmrehiFyF2ngM0QcuBqAZ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fdf83c383835fc3
Perceptual Hash:bcd3c24745836cd6
Difference Hash:e0b13eb6a6b6b4a6
Wavelet Hash:7f9fc30383838f03
Color Hash:#bf6e40

Other Hashes

Crop Resistant:e0b13eb6a6b6b4a6

Scan History

Scan history not available

Unable to load historical scan data