Security Scan Report: metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app

Redirected to:
https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/sola...
Site favicon
Submitted: Aug 17, 2026, 12:45:21 PMCompleted: Aug 17, 2026, 12:54:53 PMpubliccompleted

Summary

This website contacted 4 IPs in 1 country across 4 domains to perform 1 HTTP transaction. The main domain is metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app and was registered NaN years ago.

Submitted URL: http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/solana/connect/guides/sign-data/sign-message/

Effective URL: https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/solana/connect/guides/sign-data/sign-message/Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

The page hosts high‑severity malicious JavaScript (WebSocket C2) and is flagged by Safe Browsing as phishing, indicating malware distribution risk.

Risk Factors
Malicious JavaScript pattern (WebSocket command & control)
High obfuscation and encoded code
Safe Browsing phishing flag
Unverified phishing IoC on the subdomain
Domain age information unavailable

Details

Page Title

Sign messages | MetaMask developer documentation

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(92%)

Domain Information

The domain name 'metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'metamask-docs-l8lvh00ol-consensys-ddffed67'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus four consonants. It segments into 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/sdk/solana/connect/guides/sign-data/sign-message/

Page Load Overview

17.02s
Total Load Time
19
HTTP Requests
4
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:3,090 chars
Detector Agreement:60%

Website Classification

Primary Category

technology software92% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
92%
documentation technical
83%
cryptocurrency blockchain
36%
corporate
35%
finance banking
26%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7151.101.193.229Fastly · CDNUnited States
AS54113Fastly, Inc.
4216.198.79.195United States
AS16509Amazon.com, Inc.
464.239.109.65United States
AS16509Amazon.com, Inc.
418.245.31.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
194--

Page Statistics

19
Requests
4
Unique Domains
1.9 MB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19ED30672E1E0303F546742CEDB919B14727A94EBDA8D23D1B36C82A01BC6EDA355387D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:oyhv9iNntPosgumqm489R+ri9lOogTs1/Hj99sOiSSa9EGrqObz7kAc:odNntPosgumqmITs1Pj99s6gf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137992:ZH0OMC4AVBaIQAuJQYMHhFIiVHFAsYhGJ1dAAAFR6EDQ+4xgYHwSUEAYDuEWBIDAMiYQEuNhNcqoGCBRAKgkAAEXFxIPCwmF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffffc3838383
Perceptual Hash:bcc22c2dc3c33c6d
Difference Hash:f0b1b6e026262626
Wavelet Hash:7e9f1f3f83818181
Color Hash:#5d783a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data