Security Scan Report: agi-facil.vercel.app

Submitted: Sep 22, 2026, 10:50:09 PMCompleted: Sep 22, 2026, 10:50:48 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Fake Agibank page on vercel.app harvesting CPF and phone under a retiree 'saldo a resgatar' lure and POSTing the data to an unrelated suspicious domain — confirmed phishing.

Risk Factors
Impersonation of Agibank on a domain that is not Agibank's official site
Cross-origin exfiltration of harvested CPF/phone data to sempreatualizandoasor.online
Unranked, unknown-age subdomain on an instant-hosting platform
Classic Brazilian 'forgotten balances / values to redeem' phishing lure aimed at pensioners
Domain age information unavailable

Details

Page Title

Consulta de Valores - Agibank

Scan Type

public

Domain Name Analysis

Domain 'agi-facil.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'agi-facil'. The registrable portion 'vercel' spans 6 characters holding 2 vowels versus 4 consonants. Splitting it apart reveals two words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://agi-facil.vercel.app/

Page Load Overview

1.52s
Total Load Time
36 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-br
Text Length:385 chars
Detector Agreement:67%

Website Classification

Primary Category

cryptocurrency blockchain76% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
76%
finance banking
75%
adult content
46%
government public service
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
33--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14062749639F30041A913B8BC2BE79201723AE403944DCD797F5D5355AF8A990D5B2BEC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:Gknghzb65GqMrbW2FkFtw9NUGb9hBEJysJvvo5qrYFW9/8R6USiNFbJGk1U+M445:XYF7LF+Nv4vrFEk3OKmxhahs/dw0h

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15426:LEhBSeuYCBhQgSAJBCUIBSg0AVRhIhEgwBwCngoRGhG9QIRASKBR/RQMiyBIQE1iWAZAADB9UFmbppKqMQE0oACFUghKEDgQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff18181818000000
Perceptual Hash:dd89a6a69999b28c
Difference Hash:0c32b2b2320c0000
Wavelet Hash:fff8f8f8f8c08080
Color Hash:#1f9370

Scan History

Scan history not available

Unable to load historical scan data