Security Scan Report: kjhkjh-o4ul.vercel.app

Submitted: Oct 3, 2026, 9:54:21 PMCompleted: Oct 3, 2026, 9:54:55 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 70%

7
Risk Score

Anonymous login page on a gibberish vercel.app subdomain with hidden fields, no branding, and an ipinfo.io IP-logging beacon — a credential-harvesting pattern. Do not enter any email or password.

Risk Factors (5)
Credential (email/password) capture on a shared cloud-hosting subdomain with no verifiable operator identity
Gibberish subdomain and filename inconsistent with any legitimate product or service
Hidden form fields and an inert javascript:void(0) submit with client-side-only password validation
Cross-origin beacon to ipinfo.io typical of phishing kit victim logging
Network IDS alerts flagging the hosting namespace as an actor-abused service
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'kjhkjh-o4ul.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'kjhkjh-o4ul'. Its registrable label 'vercel' stretches across 6 characters containing 2 vowels alongside four consonants. Word splitting yields two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://kjhkjh-o4ul.vercel.app/hgcfgvgh.html

Page Load Overview

0.77s
Total Load Time
399 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:52%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:???
Text Length:221 chars
Detector Agreement:100%
Language mismatch: Declared as ??? but detected as en

Website Classification

Primary Category

finance banking30% confidence
Type: webapp
Method: ml+structural

All Detected Categories

finance banking
30%
adult content
30%
news media journalism
30%
government public service
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1564.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0142.251.110.95Google · CDNUnited States
AS15169Google LLC
0151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0142.251.20.95Google · CDNUnited States
AS15169Google LLC
0104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.151.119Google · CDNUnited States
AS15169Google LLC
0100.61.51.65Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
1517--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11A054F56AD671C890B15A07920DF2AC11B2E63DBA8468CDCB50FF7DCCFE818658E17C9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12288:6ApK3aZ6sKB2WXeqAlPf0msGTVXOuqs/wacSwTo7ode2JLoiuedEMSosV:6RGPfZsEXOuqs/UrJoV

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:832904:gjoMQyI/wGQNDiBBbCgAICgoxAJ4EiELYgSWgKqBHUpDEACkEvK4BAUFLZ4DiBAY8UMhGcAERAHlEOxkRhCJFh4AgUggIIDg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:9999666666333399
Difference Hash:4cb2b2b2b24c3000
Wavelet Hash:041c1c1c1c0c0000
Color Hash:#b279d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data