Security Scan Report: auth-secure-portal.vercel.app

Redirected to:
https://block-orcin-alpha.vercel.app/
Submitted: Sep 24, 2026, 11:50:08 AMCompleted: Sep 24, 2026, 11:50:46 AMpubliccompleted

This website contacted 6 IPs in 1 country across 6 domains to perform 18 HTTP transactions. The main domain is block-orcin-alpha.vercel.app and was registered 18 years ago.

Submitted URL: https://auth-secure-portal.vercel.app/

Effective URL:

https://block-orcin-alpha.vercel.app/
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Vercel-hosted page displays a Netflix title on a non-Netflix domain, is reported by OpenPhish as phishing, and redirects to another subdomain; treat as high-risk brand impersonation.

Risk Factors (5)
Netflix brand displayed on a non-Netflix domain.
Single-source phishing report from OpenPhish.
Redirect to a different Vercel subdomain.
Free hosting platform subdomain with unknown age.
Network IDS alerts for abuse-associated cloud hosting infrastructure.
Domain age information unavailable

Details

Page Title

Netflix

Scan Type

public

Domain Name Analysis

The domain 'auth-secure-portal.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'auth-secure-portal'. The core label 'vercel' covers 6 characters containing two vowels alongside 4 consonants. Splitting it apart reveals 2 words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://auth-secure-portal.vercel.app/

Page Load Overview

0.57s
Total Load Time
426 KB
Total Size

Language Analysis

Primary Language

🇩🇰Danish
Code: da
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:da
Text Length:7 chars
Detector Agreement:0%

Website Classification

Primary Category

cryptocurrency blockchain47% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

cryptocurrency blockchain
47%
technology software
30%
documentation technical
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
369.46.46.18Seattle, Washington, United States
AS400940Railway
3104.26.12.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.251.155.119Google · CDNUnited States
AS15169Google LLC
3142.250.154.94Google · CDNUnited States
AS15169Google LLC
186--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18DF0C9815AB04009633403402DE0F8184C59A746C2829F20BAA2A0A84FE8686CC4F96C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:h4hqC6YOLBrAMMJAGKNmI9fAbpli7vkMiBJAqIbR2+MvfWHwlT3AV4LKTj+GwlJO:hQn5KHKy7IMqsKW7VWqAEd1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:512:AAAAAAAAAAACAAEAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAAFAAAACAAAAAAAAIAAAAAAAAAAAAAAAAABEACAAAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffe7
Perceptual Hash:e6998c9966999999
Difference Hash:0000000c0c00000c
Wavelet Hash:0c0c3c24e4f4fce4
Color Hash:#bf9540

Other Hashes

Crop Resistant:0000000c0c00000c

Scan History

Scan history not available

Unable to load historical scan data