Security Scan Report: mybooking-com.vercel.app

Site favicon
Submitted: Sep 25, 2026, 8:50:37 PMCompleted: Sep 25, 2026, 8:52:43 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake Booking.com login on a vercel.app subdomain with 'Booking.com™' branding and an email/password form — classic credential phishing; avoid entering any credentials.

Risk Factors (5)
Impersonation of Booking.com brand on a non-official domain (mybooking-com.vercel.app)
Credential-harvesting login form (email + password)
Single-source phishing threat-intelligence match on the primary domain
Suricata alerts flagging actor-abused cloud hosting service
No legitimate legitimacy signals (score 5/100), unranked domain
Domain age information unavailable

Details

Page Title

Booking.com

Scan Type

public

Domain Name Analysis

The domain name 'mybooking-com.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'mybooking-com'. The core label 'vercel' covers 6 characters with 2 vowels and four consonants. Breaking it apart gives 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mybooking-com.vercel.app/login

Page Load Overview

0.84s
Total Load Time
253 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:346 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software65% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
65%
documentation technical
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
199.84.152.94Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
199.84.152.80Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
54--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1752219346A81384D8557830EFC309714933B5B9DF9DE80AC6EFC8E62D2CB6705D6A9C8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:jQhEzLdy/F6Y3q+NM51RQFYH+b2wQIhc3p2:jLvd6l3tNYUe42Zv3E

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10156:wCsBiShgIDjxvhHgUMACSGBDASkQRyMAADQBAQ6YApxkqsljdiARQUEFQJFEEMWIIpAgVOAyB4TXIhJWmAB54u0xwOiIiYJG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffc7e7ffffffff
Perceptual Hash:b371594d4d66664c
Difference Hash:9e000c0c080c0800
Wavelet Hash:000303030303273f
Color Hash:#37862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data