Security Scan Report: www.eng650.vercel.app

Redirected to:
https://eng650.vercel.app/
Submitted: Sep 19, 2026, 6:51:17 AMCompleted: Sep 19, 2026, 6:51:36 AMpubliccompleted

This website contacted 12 IPs in 1 country across 8 domains to perform 11 HTTP transactions. The main domain is eng650.vercel.app and was registered 10 years ago.

Submitted URL: https://www.eng650.vercel.app/

Effective URL:

https://eng650.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 94%

10
Risk Score

Confirmed phishing: a fake 'Webmail' login on a vercel.app subdomain drives a credential-harvesting form with a CRITICAL YARA-detected Telegram exfiltration kit and an IDS phishing alert.

Risk Factors
YARA-verified Telegram credential-exfiltration phishing kit
Credential capture form (password field) on a free-hosting subdomain
Network IDS phishing classification for webmail landing page
Cross-origin POST of visitor data to ipinfo.io
Error handling references an undefined URL, indicating a clonked/stealer kit rather than real webmail infrastructure
Domain age information unavailable

Details

Page Title

Web Mail

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'www.eng650.vercel.app' is registered with subdomain 'www.eng650'. Count 6 characters in 'vercel' containing two vowels alongside 4 consonants. Tokenizing the label suggests 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.eng650.vercel.app/

Page Load Overview

1.55s
Total Load Time
200 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:98 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical48% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
48%
finance banking
45%
news media journalism
41%
adult content
35%
phishing scam
35%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
064.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0142.251.14.95Google · CDNUnited States
AS15169Google LLC
0151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
064.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1112--

Detected Technologies8

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T142E02B8784E88C2F21A0C901ACD2F17D5CF4A91BAB449D95BDE501684FA879684E785C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:q9hqIY7YvfAbpli7vkqH8JLBpWYzvlHT8NWQAlKPUQyrNVuB9d:njy7SdWYz9z8NWQCUURNVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:4a189dc5da5320e8e61b1fdf8c956e16

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffbd3c3c00000000
Perceptual Hash:88cdcf7332666631
Difference Hash:717171711db10195
Wavelet Hash:ffffffff00000000
Color Hash:#784f3a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data