Security Scan Report: stevoluon.vercel.app

Submitted: Sep 26, 2026, 5:50:29 PMCompleted: Sep 26, 2026, 5:54:22 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Anonymous login page on a .vercel.app subdomain with an unusually weak 4-character password rule and no brand identity. No Indicators of Compromise, malware, exfiltration, or impersonation found, so evidence supports only moderate risk.

Risk Factors (3)
Credential-collecting login form on a hostname with unknown creation date (subdomain age is not attributable to this page)
Anomalously weak 4-character password requirement and generic 'Invalid password' messaging with no identifiable service or brand
Blank page title and no visible organizational identity behind a login prompt
Safety Factors (5)
No Indicators of Compromise against the page or its resources
No JavaScript malware / YARA patterns and no known malicious kit detected
No cross-origin form submission and no credential exfiltration detected (form is same-origin, JavaScript-only)
Cross-origin POST to ipinfo.io is routine geolocation use, not credential handling
Only third-party scripts are standard CDNs (Google jQuery, Cloudflare, Font Awesome, Bootstrap)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

Domain 'stevoluon.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'stevoluon'. The core label 'vercel' covers 6 characters split between two vowels and 4 consonants. It segments into 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://stevoluon.vercel.app/

Page Load Overview

1.33s
Total Load Time
344 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

Text Length:226 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1464.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0142.250.154.95Google · CDNUnited States
AS15169Google LLC
0104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.110.95Google · CDNUnited States
AS15169Google LLC
0142.251.157.119Google · CDNUnited States
AS15169Google LLC
0172.67.139.119Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
052.72.208.91Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1419--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14E74D15BA1B910C11E07F4AC26EB66407336F21BD84ADC18FA8E778CCFC564959A27CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:KFWxYakFfBJKQe3JdKdHIH9q1moB0Gw6kmK0dLdMFTeyAyj1gEMSUnfJI+RByB6O:cBBJKQe3GJxloiuedEMSoSBr1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:348064:NTgl5x4gBxKEMMHjQYI3INKYDEYkIYECMIuomMAEHYEQY7YEUmUkhIQQCQIHwGga2gAKEvESQEpYSk49AA4kKGCCx4AEbkCk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:9999666666333399
Difference Hash:4cb2b2b2b24c3000
Wavelet Hash:1c1c1c1cf8f0f0f0
Color Hash:#86bf40

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data