Security Scan Report: vd4hy6lkykz7c1p1f3q.vercel.app

Redirected to:
https://zmrk40f-h20f.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 21, 2026, 12:45:15 PMCompleted: Sep 21, 2026, 12:45:48 PMpubliccompleted

This website contacted 2 IPs in 1 country across 3 domains to perform 3 HTTP transactions. The main domain is zmrk40f-h20f.vercel.app and was registered 14 years ago.

Submitted URL: https://vd4hy6lkykz7c1p1f3q.vercel.app/sdfn45wstnrefyje5hrtbw

Effective URL:

https://zmrk40f-h20f.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 68%

7
Risk Score

Thin-content vercel.app subdomain with a hidden password field, 3 forms and 7 username inputs, reached via a redirect chain between two random-string tenants. No IoC/YARA hit, but the hidden credential field and mirrored-page IDS alert warrant avoiding interaction.

Risk Factors (5)
Hidden password field with no visible counterpart in the UI
Three forms collecting 7 username/email inputs on an empty throwaway hosting subdomain
Redirect between two random-string .vercel.app tenants
No published age for the ephemeral subdomain (could be minutes old)
Unranked in Cisco Umbrella with random, non-human-readable URL paths
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

The domain 'vd4hy6lkykz7c1p1f3q.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'vd4hy6lkykz7c1p1f3q'. Its registrable label 'vercel' stretches across 6 characters holding two vowels versus 4 consonants. Tokenizing the label suggests two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://vd4hy6lkykz7c1p1f3q.vercel.app/sdfn45wstnrefyje5hrtbw

Page Load Overview

1.00s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:12 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
32--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115A1377329E221005DEC96F568DC3B0C735EC45F0982DD67D28E283CB72FADAB499554

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F09k/N9oWUuxRk1BtG8jQ7NBp+44:TBxslWFyRk3dU2R+BtYTc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4866:4KwBABgEApJBtgKEkCGAgEBCQIIARoECEAGAAgFSCQEQIIoSAqFAAgsWCAACDCSIlEAQgJokFAAJAwAACAAlo2SFjAFDAoGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b931c6c63931c6ce
Difference Hash:0000001010000000
Wavelet Hash:30303000c0f0f0f0
Color Hash:#1f4293

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data