Security Scan Report: orangeverification.vercel.app

Site favicon
Submitted: Sep 26, 2026, 1:50:08 AMCompleted: Sep 26, 2026, 1:50:44 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Orange phishing page on a vercel.app subdomain: it collects email and password and exfiltrates them to an external Telegram endpoint, with victim IP geolocation. Do not enter credentials.

Risk Factors
Brand impersonation of Orange on a non-official domain
Credential-harvesting password form collecting Orange account credentials
JavaScript sends captured email and password to an external Telegram endpoint (credential exfiltration)
Victim geolocation via ipapi.co and api.ipify.org external requests
Hosted on instant/free vercel.app subdomain, unranked, unknown creation date
Domain age information unavailable

Details

Page Title

Vérification Orange

Scan Type

public

Domain Name Analysis

Domain 'orangeverification.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'orangeverification'. The registrable portion 'vercel' spans 6 characters containing two vowels alongside 4 consonants. Tokenizing the label suggests 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://orangeverification.vercel.app/

Page Load Overview

3.03s
Total Load Time
505 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:3,473 chars
Detector Agreement:67%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.19.229.21Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.19.230.21Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
95--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117D2C66225F30C122547D168BB6BD7463524C543E10BDA287BAC938CAFCBED689237DD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:xI0AS/tLoKEFYL4taM+W6WsbdHYWTeYJ4uZr6U1:IytE6M+5LN91

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:30165:gEXIEMLCsCCBMUANGQUACIGsOSUQdSKBKYHeEQmAAmYZqEgDp6ZgAEAFrAU5ECJOhYqhUAoQCBCLhKHFwWkJLGuFDpIiCFAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fffffffff7ff0000
Perceptual Hash:e7b319a6469c1933
Difference Hash:0c4c48304c083010
Wavelet Hash:c3e7e7e7273f0000
Color Hash:#ac53a9

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data