Security Scan Report: coderlog-two.vercel.app

Submitted: Sep 21, 2026, 12:45:12 AMCompleted: Sep 21, 2026, 12:45:36 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 85%

3
Risk Score

Fake PayPal login on a free vercel.app subdomain, collecting email/mobile credentials — classic brand-impersonation phishing. Avoid and report.

Risk Factors
Impersonation of PayPal brand on a non-PayPal, free vercel.app subdomain
Credential-collecting login form (email/mobile number) on an unrelated host
Unranked domain not present in Cisco Umbrella top 1M, inconsistent with a major payment provider
Network IDS alerts for .to TLD DNS queries and actor-abused cloud hosting
Safety Factors
No JavaScript malware patterns detected by YARA
No threat-intel Indicators of Compromise matches against page or loaded resources
No password or payment fields captured in the DOM
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 3
Domain age information unavailable

Details

Page Title

PayPal

Scan Type

public

Domain Name Analysis

The domain name 'coderlog-two.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'coderlog-two'. The second-level label 'vercel' is 6 characters long split between two vowels and four consonants. Splitting it apart reveals 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://coderlog-two.vercel.app/

Page Load Overview

1.95s
Total Load Time
214 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:56 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking53% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
53%
e-commerce shopping
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
264.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
145.43.142.6United Kingdom
AS16276OVH SAS
1172.66.161.212Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
145.43.142.4United Kingdom
AS16276OVH SAS
54--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D27133AB29D31452A543D5642FF6DA4532E6A013C149CD253EDE2688CF8E7D98CA27CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TmKb7TwKxcNFAhTXy5B5NBKv6kJ1aXV+DvxO:aKb7MKxcNFAhTXy/HgCkJkojxO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3761:ABBBAgABQEAACAYKQAwGAAEAiQBCAEAhwDoAIQgBaEAASSwUBgAACAQFJAgCEIAFIgCgKQgC0AAgIAACCICAQAAEFIgYmAgC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7ffa5e7ffe7ff
Perceptual Hash:b333cccc3333998c
Difference Hash:000c324d0c320800
Wavelet Hash:c0c0d8c0d8d8f0f0
Color Hash:#93401f

Other Hashes

Crop Resistant:000c324d0c320800

Scan History

Scan history not available

Unable to load historical scan data