Security Scan Report: bnimail-owa.vercel.app

Redirected to:
https://bnimail-owa.vercel.app/
Submitted: Sep 20, 2026, 12:45:32 AMCompleted: Sep 20, 2026, 12:46:18 AMpubliccompleted

This website contacted 2 IPs in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is bnimail-owa.vercel.app and was registered 6 years ago.

Submitted URL: http://bnimail-owa.vercel.app/

Effective URL:

https://bnimail-owa.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed Outlook credential-phishing page on a vercel.app subdomain; its login form exfiltrates usernames and passwords to an external submit-form.com endpoint. Do not enter credentials.

Risk Factors
Brand impersonation of Microsoft Outlook on a non-Microsoft domain
Credential (username + password) form posting to an external cross-origin endpoint (submit-form.com)
Threat-intel phishing report on the primary domain
IDS HIGH alert for landing-page form exfiltration
Subdomain created on an actor-abused cloud hosting platform (vercel.app) with unknown age
Domain age information unavailable

Details

Page Title

BNI Outlook

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'bnimail-owa.vercel.app' is registered, featuring subdomain 'bnimail-owa'. The core label 'vercel' covers 6 characters containing two vowels alongside four consonants. It segments into two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://bnimail-owa.vercel.app/

Page Load Overview

1.95s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:544 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software83% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
83%
documentation technical
81%
government public service
67%
news media journalism
66%
healthcare medical
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
264.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
42--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T121439E3FA9572C332827607463EBB28A3B2AC417864ED924387C1758EF41D76417EBD9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:gyDwuJmtz7e05Nnfvi2aD2xUkzdKV7aQblNoJmgK4e2FuzqQnclYtcY:ytzK05N7aD2xUEkF5F4nFuVcScY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57527:KeEKQI1AVgJAYCgiXggMQqIHEAAEpJgI+4IOBQWNmKGwASCfBA5FQRoe6oPgJAADw1C6yKKYg+DCFoAagwoEiYTBSIxSCKRE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd0d8d0d0d0
Wavelet Hash:3f273f3f3f000000
Color Hash:#1f8293

Scan History

Scan history not available

Unable to load historical scan data