Security Scan Report: bnimail-owa.vercel.app

Submitted: Sep 27, 2026, 4:50:02 AMCompleted: Sep 27, 2026, 4:50:36 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Fake Outlook login on a vercel.app subdomain that harvests email and password and exfiltrates them to submit-form.com. Brand impersonation plus cross-origin credential theft and a phishing threat-intel hit.

Risk Factors (5)
Brand impersonation of Microsoft Outlook on an unrelated vercel.app subdomain
Credential-harvesting login form (password + email fields) on a shared hosting platform tenant
Cross-origin credential exfiltration to submit-form.com form backend
Threat-intel phishing report on the primary domain
Free hosting subdomain, no ranking, unknown actual page age — no legitimate corporate identity
Domain age information unavailable

Details

Page Title

BNI Outlook

Scan Type

public

Domain Name Analysis

You're looking at domain 'bnimail-owa.vercel.app' on the application-focused generic top-level domain (.app), featuring subdomain 'bnimail-owa'. The registrable portion 'vercel' spans 6 characters with 2 vowels and 4 consonants. Segmentation suggests two words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bnimail-owa.vercel.app/

Page Load Overview

0.41s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:544 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software83% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
83%
documentation technical
81%
government public service
67%
news media journalism
66%
healthcare medical
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
33--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T121439E3FA9572C332827607463EBB28A3B2AC417864ED924387C1758EF41D76417EBD9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:gyDwuJmtz7e05Nnfvi2aD2xUkzdKV7aQblNoJmgK4e2FuzqQnclYtcY:ytzK05N7aD2xUEkF5F4nFuVcScY

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:57527:KeEKQI1AVgJAYCgiXggMQqIHEAAEpJgI+4IOBQWNmKGwASCfBA5FQRoe6oPgJAADw1C6yKKYg+DCFoAagwoEiYTBSIxSCKRE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3f3f3f3f3f3f3f3f
Perceptual Hash:83f677010989d9fc
Difference Hash:d0ccccd8d8d0d0d0
Wavelet Hash:3f273f3f3f330000
Color Hash:#1f2993

Scan History

Scan history not available

Unable to load historical scan data