Security Scan Report: cancelcardiffbahora.vercel.app

Site favicon
Submitted: Sep 26, 2026, 7:50:05 PMCompleted: Sep 26, 2026, 7:50:39 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Fake 'Seguros Cardiff Bancolombia' cancellation page on a free vercel.app subdomain impersonating Bancolombia, with a phishing report against its own domain. Avoid entering any personal data.

Risk Factors (5)
Impersonation of Bancolombia brand on a non-official vercel.app domain
Single-source phishing Indicator of Compromise on the primary domain
IDS alerts flagging vercel.app as commonly actor-abused cloud hosting
Solicits personal data under the guise of cancelling a 'Seguro Cardiff' policy
Unranked domain with unknown subdomain age on a free hosting platform
Domain age information unavailable

Details

Page Title

Seguros Cardiff | Bancolombia

Scan Type

public

Domain Name Analysis

Domain 'cancelcardiffbahora.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'cancelcardiffbahora'. Its registrable label 'vercel' stretches across 6 characters containing two vowels alongside four consonants. Tokenizing the label suggests 2 words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cancelcardiffbahora.vercel.app/

Page Load Overview

1.46s
Total Load Time
365 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:2,203 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service87% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
87%
finance banking
86%
corporate business
73%
healthcare medical
70%
news media journalism
65%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5142.251.20.95Google · CDNUnited States
AS15169Google LLC
5192.178.183.94Google · CDNUnited States
AS15169Google LLC
564.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
234--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T130D29217A1F22137A4139D55B7F26F5E6168C103E40885787A9C12C8CFFADE9DDA3A8C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:gvh+QroRB+HQ+VA2+g9mDM6F+YNdJrfBRWDyQ9lzjKFswL0ibWMlrdKPx5+DVONf:gvhzcyJStFqFXw04uNxyIItj8CgjnAfA

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29068:IKWACAXC6FQK0Zgu5CaMBh4AGBA9KAFFzoCYkY6PXBENABRIAEwrhhA3ogDabAM0AAQJwMHe1UBCgAkKhPD8FIYxXYhNCA28

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff002020203000ff
Perceptual Hash:8368bc15fa43c3bc
Difference Hash:9dd5c5cdc4c4dccc
Wavelet Hash:ff006070347e06ff
Color Hash:#86bf40

Scan History

Scan history not available

Unable to load historical scan data