Security Scan Report: metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app

Redirected to:
https://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask...
Site favicon
Submitted: Sep 7, 2026, 1:45:15 PMCompleted: Sep 7, 2026, 1:46:48 PMpubliccompleted

This website contacted 9 IPs in 1 country across 11 domains to perform 19 HTTP transactions. The main domain is metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app and was registered 6 years ago.

Submitted URL: http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask-connect/troubleshooting/

Effective URL:

https://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask...
Redirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Page contains malicious JavaScript (C2 backdoor) and phishing IoCs; treat as high‑risk malware distribution.

Risk Factors
Malicious JavaScript pattern indicating command‑and‑control activity
Phishing indicators from openphish.com (unverified but present)
Unranked, untrusted subdomain on a shared hosting platform
Domain age information unavailable

Details

Page Title

Troubleshooting - MetaMask Connect | MetaMask developer documentation

Scan Type

public

Domain Name Analysis

You're looking at domain 'metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app' on the application-focused generic top-level domain (.app), featuring subdomain 'metamask-docs-p13jojaa8-consensys-ddffed67'. Count 6 characters in 'vercel' containing 2 vowels alongside four consonants. It segments into 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask-connect/troubleshooting/

Page Load Overview

1.29s
Total Load Time
1.9 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,885 chars
Detector Agreement:80%

Website Classification

Primary Category

technology software89% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
89%
documentation technical
81%
cryptocurrency blockchain
68%
corporate
35%
cryptocurrency
30%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.239.123.1United States
AS16509Amazon.com, Inc.
218.245.31.112Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
2151.101.1.229Fastly · CDNUnited States
AS54113Fastly, Inc.
2216.198.79.67United States
AS16509Amazon.com, Inc.
264.239.123.65United States
AS16509Amazon.com, Inc.
218.245.31.78Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
2216.198.79.195United States
AS16509Amazon.com, Inc.
2104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
264.29.17.195United States
AS16509Amazon.com, Inc.
199--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AB71EF77E210F82C775756F4B522B048C3A2E70BDA9D6C0171EC03B56AECA64A1F7953

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hc4X3XkvWSSDbDP2gi4gobAspGoHefegPe28udo2/jbuujlo2/811B6C2GuPe2cp:SsUvWXgmATWgGi1HedSzFrNEEc6am9W

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3731:ICAgEpTSkCCAJAUWBAAIAEQQkFAGBCAEMAFBBAAQBAACFQkAACEggAAAhECKIAQwDAqAAQAgAUBAICAIBiFBAEkALAgAEAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffdf0f3f3f2f3f
Perceptual Hash:81fcfa0378797c03
Difference Hash:94a0b6befadadac6
Wavelet Hash:007f03073f3f2337
Color Hash:#93841f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data