Security Scan Report: super-sim-alpha.vercel.app

Submitted: Sep 23, 2026, 3:50:15 PMCompleted: Sep 23, 2026, 3:51:03 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Unverified 'SuperSim' instant-loan landing page on a free vercel.app subdomain with a mismatched contact-email domain. No forms, malware, or threat-intel hits — moderate suspicion from financial-scam framing, not confirmed phishing.

Risk Factors (4)
Free hosting-platform subdomain (vercel.app) with unverifiable creation date
Company name vs. contact-email domain mismatch (SuperSim vs. agilizacred.com.br)
Unverifiable guaranteed-lowest-rate loan offer with fabricated-style testimonials
Domain not present in Cisco Umbrella top 1M
Safety Factors (6)
No Indicators of Compromise matched against the page or its resources
No JavaScript/YARA malware patterns detected
No credential, password, or payment forms present (0 forms)
No cross-origin credential exfiltration detected
No known malicious kit in the analyst-vetted kit roster
Page presents its own brand (self-branding), not impersonation of another entity
Domain age information unavailable

Details

Page Title

SuperSim – Crédito Pessoal Pré-Aprovado

Scan Type

public

Domain Name Analysis

The domain name 'super-sim-alpha.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'super-sim-alpha'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus four consonants. Tokenizing the label suggests two words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://super-sim-alpha.vercel.app/

Page Load Overview

2.44s
Total Load Time
599 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-BR
Text Length:2,020 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking75% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
75%
technology software
49%
corporate business
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
16216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.110.95Google · CDNUnited States
AS15169Google LLC
1104.26.10.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1172.67.68.221Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1172.67.74.194Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
1192.178.183.94Google · CDNUnited States
AS15169Google LLC
1104.18.38.10Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3116--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BBD2429B2A630255BD13A9796FEB5B066374D003C50ACDB93FCD624CCF853D86A9278C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:yNvV0ZoUT+a735yZF5FlczBeXG3FYFGiEvQis:IUTt735yZnKBeXG3G0iEvQis

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:28716:IJgJIcigJaIQVAFPWJxiFhQdcUkYtCKBGig1BByIWE0sggAotRDhoYI2IAhCERxBBGIZNxCUDWAkIhCAQU9MDaBi4rA4RSwo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:070000003fffffff
Perceptual Hash:890cf3f388a3f3c8
Difference Hash:57f3f7f3b3181b1a
Wavelet Hash:070000001fffffff
Color Hash:#2d6486

Scan History

Scan history not available

Unable to load historical scan data