Security Scan Report: american-express-applications.vercel.app

Submitted: Sep 19, 2026, 12:45:28 PMCompleted: Sep 19, 2026, 12:46:05 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake American Express login hosted on a vercel.app subdomain, presenting a brand-impersonating credential form to harvest usernames and passwords. Avoid entering any details.

Risk Factors
Impersonation of the American Express brand on a non-official domain
Credential-harvesting login form (username + password fields)
Hosted on a free shared-hosting subdomain (.vercel.app) with unknown creation date
Unranked domain (not in Cisco Umbrella top 1M) despite claiming a major financial brand
Uses official AmEx static assets (aexp-static.com) to mimic the genuine login page
Domain age information unavailable

Details

Page Title

American Express - Login

Scan Type

public

Domain Name Analysis

The domain name 'american-express-applications.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'american-express-applications'. Count 6 characters in 'vercel' with two vowels and four consonants. Breaking it apart gives two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://american-express-applications.vercel.app/

Page Load Overview

0.44s
Total Load Time
4 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:202 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism40% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

news media journalism
40%
corporate business
35%
finance banking
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
023.52.181.182Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
0216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
02.22.113.225Akamai · CDNVienna, Vienna, Austria
AS16625Akamai Technologies, Inc.
064.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
35--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T141C19762AA66001772F6D1A479E3670A7064C003E142DF5D7EE86758CFEBE86D5A334C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TCrjKLiaPmnaRfPPajVTRyZRWyIwOuNjxnIRZ8Mm6bkGqzHm:GrjKuxnuPajVdyL+uvq8Mm6/IHm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5999:UigwwQQAIBILCFiDwAAACIQBgEhgSAAVQRIBgDBaAXgJDdQBlAouIEIexAsAACFABCQggFAjgKUUYIAJAQgMGwiwBIEAQBgI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffe7ffffff
Perceptual Hash:b33a183a32595977
Difference Hash:3129324c4c300800
Wavelet Hash:0018100003030303
Color Hash:#59862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data