Security Scan Report: 8qot0mzb8mhrkq2iwbs.vercel.app

Redirected to:
https://xjml55s-h20s.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 21, 2026, 12:45:06 PMCompleted: Sep 21, 2026, 12:45:27 PMpubliccompleted

This website contacted 8 IPs in 1 country across 5 domains to perform 22 HTTP transactions. The main domain is xjml55s-h20s.vercel.app and was registered 10 years ago.

Submitted URL: https://8qot0mzb8mhrkq2iwbs.vercel.app/sdfn45wstnrefyje5hrtbw.html

Effective URL:

https://xjml55s-h20s.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 72%

8
Risk Score

Credential-harvesting page on a rotating Vercel subdomain: 3 forms with 7 username fields and a hidden password field, multi-hop redirects, IDS phishing alert, and geo-localization scripts. Avoid entering any credentials.

Risk Factors (6)
Hidden password field present in DOM but invisible to the user
7 email/username fields across 3 forms on a throwaway-looking subdomain
Multiple redirects across randomized Vercel subdomains
IDS phishing alert (mirrored website) plus abused-cloud-hosting alerts for vercel.app
No domain reputation: unranked in Cisco Umbrella, subdomain creation date unknown
Geo/IP localization scripts (ipapi.co, flagcdn.com) on a login-style page
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

The domain name '8qot0mzb8mhrkq2iwbs.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain '8qot0mzb8mhrkq2iwbs'. Count 6 characters in 'vercel' with two vowels and four consonants. It segments into two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://8qot0mzb8mhrkq2iwbs.vercel.app/sdfn45wstnrefyje5hrtbw.html

Page Load Overview

1.16s
Total Load Time
548 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:12 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
264.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
264.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2151.101.65.229Fastly · CDNUnited States
AS54113Fastly, Inc.
2104.26.9.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.21.31.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.180.104Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
228--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115A1377329E221005DEC96F568DC3B0C735EC45F0982DD67D28E283CB72FADAB499554

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F09k/N9oWUuxRk1BtG8jQ7NBp+44:TBxslWFyRk3dU2R+BtYTc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4866:4KwBABgEApJBtgKEkCGAgEBCQIIARoECEAGAAgFSCQEQIIoSAqFAAgsWCAACDCSIlEAQgJokFAAJAwAACAAlo2SFjAFDAoGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b9c6c63139c6c639
Difference Hash:0000001010000000
Wavelet Hash:f0f0f0c0c0f0f0f0
Color Hash:#ac6553

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data