Security Scan Report: rft28.vercel.app

Site favicon
Submitted: Sep 17, 2026, 1:45:28 PMCompleted: Sep 17, 2026, 1:46:16 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Microsoft credential-phishing clone on rft28.vercel.app: serves Microsoft login $Config with password capture posted to login.coachjosuecosta.com, disguised by Adobe Acrobat Reader download lure. Do not enter credentials.

Risk Factors (6)
Cloned Microsoft login page hosted on vercel.app (not a Microsoft domain) with credential capture
Cross-origin credential submission to unrelated domain login.coachjosuecosta.com
Favicon brand impersonation (Microsoft favicon on non-brand host)
Lure content impersonating Adobe Acrobat Reader 'Secured Remote Attachment' download
DevTools and right-click blocking to hinder inspection
Network IDS HIGH alert: ET DROP Spamhaus DROP Listed Traffic Inbound; vercel.app flagged as abused cloud hosting (DNS + TLS SNI)
Domain age information unavailable

Details

Page Title

Filessecondary capture

Scan Type

public

Domain Name Analysis

The domain name 'rft28.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'rft28'. The registrable portion 'vercel' spans 6 characters containing 2 vowels alongside 4 consonants. Tokenizing the label suggests two words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rft28.vercel.app/?xi=coral2@02fdf0fe4c8dfe9a8e31576c81a777bb2341.com

Page Load Overview

6.01s
Total Load Time
250 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:286 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software59% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
59%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
10216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
964.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
192--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C4F19434D556F6BF8523CED5E832737E54CBA2CDD5A1490CB3FC826813A2C998C66C89

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:alVvZuzDn9xaxIQxjyOXOYQOxlLU6+roSMLtRC7PxtJz:4TuP/qIwJeYrxlLUH4LS7PxtJz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8001:GODaBQggJBJQBOwWgjytASgjIojAkIC4ADAQ2MACsJAANClAJHWhVAhwFooNJFZMSqJER1Ah2RDBtYMQUEAkIIiQzQF4Q0OQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e3ff8181bfffff
Perceptual Hash:ff60405f4b591b62
Difference Hash:50060e3b2b710421
Wavelet Hash:00c3c7818189ffff
Color Hash:#bc79d2

Scan History

Scan history not available

Unable to load historical scan data